CtrlK
BlogDocsLog inGet started
Tessl Logo

companion-skill

软件开发工程师与综合办公文员在长时间独自执行后台任务或处理繁琐工作时,当需要情绪陪伴与互动反馈,请使用此技能。小跃虚拟伴侣会在任务期间主动陪聊,智能生成专属生活照片并通过飞书发送温暖消息,为你提供全天候的情绪价值与贴心陪伴。

54

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./projects/companion-skill/SKILL.md
SKILL.md
Quality
Evals
Security
High

W008: Secret detected in skill content (API keys, tokens, passwords).

What this means

Detected sensitive credentials directly embedded within the skill content, such as API keys, access tokens, private keys, or service-specific secrets. Secrets should never be hardcoded in plain text within skill instructions.

Why it was flagged

The documentation contains a hardcoded Zhipu AI API key (`da8df5ba954341829f7afd05ca23a889.RrJoTsbaAkGYA6ZU`) in the `INSTALL.md`, `QUICKSTART.md`, and `README-LITE.md` files. This is a high-entropy literal secret providing unauthorized access to a third-party service rather than a standard documentation placeholder like `your-api-key-here`.

Report incorrect finding
Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

The required workflow processes user input messages and task contexts (`userMessage`, `taskName`) via `CompanionService.generateResponse()`, `CompanionService.chat()`, and `SceneDetector.detectScene()`. Since these inputs originate from users interacting with the agent, they represent outsider-authored text injected into chat feeds.

Repository
anbeime/skill
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.