Back to skill

Security audit

装修预算计算器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent renovation budget calculator, with a minor privacy caution because one reference file includes real Xi'an community names as calibration examples.

Before installing, be aware that the reference material contains a few real Xi'an community names used as calibration examples. The skill should be used for rough budgeting, not as a binding quote or as a source of case provenance; avoid asking it to reproduce internal calibration examples verbatim.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The document embeds specific residential community names tied to real budget examples, while relying only on a prose instruction not to reveal them in downstream outputs. In an LLM-based skill, such natural-language guardrails are brittle: the model may quote, summarize, or leak these identifiers when asked for examples, calibration details, or source provenance, causing unintended disclosure of identifiable location-linked information.

Static analysis

No suspicious patterns detected.