CtrlK
BlogDocsLog inGet started
Tessl Logo

bug-hunter

根据用户给出的行业名称(或默认使用热点社会新闻),抓取最新新闻热点,用"找世界bug"的视角——找出那些打眼一看就不合理的地方——深度分析根因、利益链条、监管盲区,并给出多维度解决思路,输出图文并茂(含SVG/Mermaid/ASCII图形)的Markdown文件,保存到项目markdown/目录。 触发条件:用户提到"找bug"、"社会bug"、"不合理现象"、"帮我分析这个行业的问题"、"帮我找新闻里的bug"、"找热点新闻的漏洞"、"有什么不合理的地方"、"帮我分析为什么会这样"、"bug猎手"等。即使用户只说"帮我找找最近有什么奇怪的新闻"或"这个行业有哪些不合理",也应使用本 skill。

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

SKILL.md 的 Step 1/Step 1.5 依赖“搜索热点新闻”并在 Step 1.5 展示“Bug候选”的事件信息;这些事件通常来自运行时抓取/检索的公开新闻页面(外部来源),其摘要/正文可能成为 LLM 上下文中的自由文本,从而带来间接提示注入风险。

Report incorrect finding
Repository
digoal/blog
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.