CtrlK
BlogDocsLog inGet started
Tessl Logo

product-review-report

编写专业产品评测报告,站在用户决策者与使用者双重视角深度评测产品。输入产品名称(以及可选的产品资料/链接、功能点、使用场景、竞品),自动搜集产品信息、竞品对比数据与行业数据,生成结论清晰、逻辑严谨、有理论依据与数据支撑、图文并茂的 Markdown 评测报告(SVG 图以外挂文件形式引用),输出到项目 markdown/ 目录。触发条件:用户提到"产品评测"、"写评测报告"、"帮我评测XX"、"product review"、"产品对比报告"、"帮我写XX的评测"、"功能评测"、"这个产品怎么样"、"XX和YY哪个更好"、"帮我做个产品调研"、"竞品分析"、"选型报告"。即使用户只提供了产品名称和希望"帮我看看这个产品",也应立即使用本 skill。

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

在“第二步:信息搜集与研究”中通过 web_search/web_fetch 在运行时抓取公开网页内容(可能包含他人撰写的自由文本,如用户评价/投诉/事故描述),再把该抓取文本用于生成报告,从而存在间接提示注入风险。

Report incorrect finding
Repository
digoal/blog
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.