CtrlK
BlogDocsLog inGet started
Tessl Logo

industry-deep-explainer

快速且通俗易懂地讲透一个行业,输出图文并茂的深度分析 Markdown 报告,保存到当前项目的 markdown/ 目录。触发条件:用户输入一个行业名称,并希望获得全面、通俗易懂的行业深度分析,关键词包括"讲透"、"深度分析行业"、"行业分析"、"帮我搞懂XX行业"、"XX行业是怎么赚钱的"、"XX行业有什么机会"、"XX行业怎么进入"、"产业链分析"、"行业机会"等。即使用户只说"帮我了解一下XX行业"或"XX行业值得进入吗",也应使用本 skill。输出报告覆盖:产业链分布与利润图谱、供给-需求-连接分析、人货场分析、代表企业与产品分析、产业链不合理之处、机会推演与进入策略(产品/服务/目标客户/商业模式/定价/市场规模)、竞争对手与合作伙伴分析,要求逻辑清晰、有理论依据、有历史数据/事件支撑、图文并茂(SVG/Mermaid/ASCII图)。

74

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

SKILL.md Step 1 requires runtime web_search/web_fetch of 1–2 web pages/reports, so the LLM will ingest outsider-authored free text scraped from public URLs (potential indirect prompt injection via fetched page content).

Report incorrect finding
Repository
digoal/blog
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.