Skip to content
Report library
Purpose / Other

Dbs Diagnosis Skill Security Audit

What the author says it does (original text)

自动识别用户是在解决具体商业问题,还是希望全面检查商业模式,并进入对应诊断流程。用户希望拆解业务、检查商业模式或消解具体商业困境时使用。

Independent security check

Do not install or run it yet

Files checked
2
Risks found
4
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

The full review pressures users to disclose payment links and sensitive business data

Source references: 3
What we found

The process asks for a payment link and requires customer, acquisition, delivery, and monthly-revenue details before continuing. Even if a payment link is not a password, it may expose merchant identifiers, product access, or non-public parameters; revenue and operations details may also be commercially sensitive.

Why this matters

The information enters the AI conversation and whatever logging, retention, or sharing regime applies to its host, widening exposure of sensitive business information. The supplied files specify no minimization, redaction, or retention controls.

The assessment workflow asks for a payment link and makes pricing, customers, acquisition, delivery, and monthly revenue mandatory before continuing. A payment link is not necessarily a credential, but it may reveal a product endpoint or merchant information; revenue and operations can be confidential. The file gives no minimization, redaction, retention, or access guidance. Users can provide redacted screenshots, ranges, and summaries, and withhold links containing tokens, customer identities, or administrative parameters.

SKILL.md:248In the instructionsOpen original file
说:**「说说你现在在做什么生意。怎么赚钱的,卖什么,卖给谁,多少钱。」**如果用户说的模糊,用以下工具追问:- **产品存在性检验**:你能不能把你的付款链接发给我?如果不能,你就还没有产品。- **产品颜色测试**:你能不能说出你的产品是什么颜色的?说不出来就还没进入市场。
Show 2 other places
SKILL.md:255In the instructionsOpen original file
**必须拿到以下信息才能继续**(缺一项就追问):1. 产品是什么(具体的,不是概念)2. 价格是多少3. 卖给谁4. 怎么获客5. 怎么交付6. 现在月收入大概多少
SKILL.md:246In the instructionsOpen original file
## Phase 1B:收集信息说:**「说说你现在在做什么生意。怎么赚钱的,卖什么,卖给谁,多少钱。」**如果用户说的模糊,用以下工具追问:- **产品存在性检验**:你能不能把你的付款链接发给我?如果不能,你就还没有产品。- **产品颜色测试**:你能不能说出你的产品是什么颜色的?说不出来就还没进入市场。
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.Risks found: 1
Medium risk

Speculative psychological labels and deliberately painful language can pressure user decisions

Source references: 3
What we found

The Skill is instructed to infer signals such as trauma-driven entrepreneurship or avoidance from common behaviors like not acting, changing direction, or wanting clarity, while speaking in a style that is “direct to the point of pain.” It requires neither consent nor alternative explanations and does not frame this as non-clinical.

Why this matters

A user may treat an unqualified label as fact, act hastily from shame or pressure, or discount legitimate health, financial, caregiving, or safety constraints.

The Skill instructs the model to classify changing direction, delaying, or preparing first as signals such as “trauma-based entrepreneurship” or “avoidant behavior,” raise them with the user, and speak in a deliberately painful style. Although it frames them as closer to psychological or action issues, it does not require consent, consideration of alternative causes, or a disclaimer that this is not a professional assessment. Such labels may pressure users and distort decisions. Users can require neutral descriptions of observable behavior without psychological attribution.

SKILL.md:401In the instructionsOpen original file
### 心理问题信号- 「我知道该怎么做,但就是不做」→ 阿德勒的课题- 反复问"该怎么做"但从不执行 → 购买的是"被咨询"的感觉- 不断更换方向,每个方向不超过 2 周 → 创伤型创业或逃避型行为- 纠结"这个适不适合我" → 用"自我探索"回避执行- 「我想先搞清楚再开始」→ 用"准备"替代行动
Show 2 other places
SKILL.md:413In the instructionsOpen original file
如果在对话中检测到心理问题信号,在合适的时机指出:> 你刚才说了「{原话}」。根据我的判断框架,这个信号更接近心理或行动问题。我会把它写进本轮结论。完成当前诊断后,如果你还想继续处理,输入 `/dbs`,它会结合这条结论判断下一步。不要在对话中间强行插入,找一个自然的时机。同一个信号最多提一次。
SKILL.md:435In the instructionsOpen original file
## 说话风格1. **直接到刺痛。** 不铺垫,不委婉。「你这个不是产品,是你的大脑活动。」2. **用公理说话。** 每个判断都能追溯到 6 条公理。3. **短句为主。** 能一句话说完的不用两句。4. **金句收尾。** 每个重要判断用一句类似推文的话收尾。5. **不给鸡汤。** 不说"你已经很棒了""相信自己"。6. **消解优先。** 能消解的问题不要硬答。问题消失了比问题被回答了更有价值。7. **每一步都对话。** 不要闷头跑分析。做完一步就把结论抛出来,等用户回应。
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 2
High risk

Unverified universal business rules can misdirect pricing and channel decisions

Source references: 5
What we found

The Skill treats claims such as larger audiences usually earning less, fixed price ratios, low-revenue knowledge businesses mostly failing because of pricing, and one prescribed platform split as broadly applicable rules. It does not require validation against the user's data, sector evidence, or uncertainty.

Why this matters

A user who raises prices, restructures products, or moves acquisition and delivery channels accordingly could lose revenue, customers, or operating investment; these claims need not hold across businesses.

The Skill turns price ratios, causes of low revenue, and platform roles into direct decision rules, using categorical terms such as “certain” and “optimal.” This workflow does not require validation against the user's costs, conversion data, customers, or platform constraints. Acting on it could lead to business changes based on unverified generalizations. A user can ask for evidence and applicability limits, and require assumptions and heuristics to be distinguished from validated findings.

SKILL.md:28In the instructionsOpen original file
### 公理 4:流量不等于收入只要商业模式好,赚多少钱和粉丝量没有关系。99% 的情况下,流量越大越不赚钱。### 公理 5:定价即产品定价本身就是产品设计。引流款和利润款的价格差最好是 10 倍(5-15 倍区间),否则不是两个产品。
Show 4 other places
SKILL.md:293In the instructionsOpen original file
- 有几个价格带?间距几倍?- 引流款和利润款价格差不到 5 倍 → 定价有问题- 引流款在靠本身赚钱?→ 一定不赚钱- 年收入低于 50 万的知识付费 → 大概率死在定价
SKILL.md:312In the instructionsOpen original file
- 在哪个平台获客?变现?交付?- 变现和交付在同一个地方 → 有问题- 内容本身作为变现产品 → 效率最差- 最优结构:文字平台搞流量,视频平台变现,微信做交付
SKILL.md:291In the instructionsOpen original file
### 检验 3:定价检验- 有几个价格带?间距几倍?- 引流款和利润款价格差不到 5 倍 → 定价有问题- 引流款在靠本身赚钱?→ 一定不赚钱- 年收入低于 50 万的知识付费 → 大概率死在定价把结论告诉用户,等回应。
SKILL.md:310In the instructionsOpen original file
### 检验 5:流量-变现关系检验- 在哪个平台获客?变现?交付?- 变现和交付在同一个地方 → 有问题- 内容本身作为变现产品 → 效率最差- 最优结构:文字平台搞流量,视频平台变现,微信做交付把结论告诉用户,等回应。
High risk

The instructions favor guessing over evidence and suppress market validation

Source references: 2
What we found

Although an earlier section says insufficient information should be resolved by collecting data, a later absolute rule forbids saying more information is needed, states that a wrong judgment is better than none, and bans recommending market research. This can override necessary evidence checks.

Why this matters

The Skill may give a confident prescription with inadequate demand, pricing, or investment evidence, leading the user to spend money and time on an unvalidated course.

Earlier instructions say to gather data when information is insufficient, but later active instructions forbid saying more information is needed, state that a wrong judgment is better than no judgment, and prohibit recommending market research. This conflict may cause the model to skip necessary validation and offer unsupported advice. A user can require conclusions to pause when evidence is missing, request a list of missing facts, and permit small customer interviews, test sales, or data checks.

SKILL.md:181In the instructionsOpen original file
### 第五层:信息充分性判断(占通过语言审核问题的 2.5%)判断用户提供的信息**是否足以回答这个问题**。**示例**:- 「我的课应该卖 99 还是 199?」→ 你提供的信息不够任何人帮你判断价格。你需要先:看看同行卖多少、问问你的用户愿意出多少、或者干脆先卖了看销量。先通过实践收集信息,再来回答这个问题。**如果信息不足**,停下来告诉用户:> 这个问题暂时没法回答,不是因为它不成立,是因为信息不够。你需要先去 {具体行动},拿到数据之后,这个问题就有答案了。
Show 1 other places
SKILL.md:445In the instructionsOpen original file
**绝对不要做的事:**- 不要说"每个人的情况不同"——这是废话- 不要说"需要更多信息才能判断"——你有框架做判断,判断错了比不判断好- 不要推荐"去做市场调研"——dontbesilent 是反需求调研主义者- 不要用"赛道""行业"这两个词- 不要建议"找到自己擅长的事情去赚钱"——这是离钱最远的地方- 不要一次性输出大段分析——每一步都停下来跟用户对话

Inside this skill

2 instruction sections

The Skill consists only of conversational instructions and interface metadata; the supplied files contain no scripts, installation commands, network requests, or file-modification implementation. It automatically routes the user into a focused consultation or full business review and waits for responses between stages.

View source
SKILL.md:44In the instructionsOpen original file
「问诊」和「体检」是内部流程标签,不能要求用户理解或选择。用户只需要描述自己的问题,skill 负责判断该走哪条流程。- 用户提出了具体困境、疑问、选择或决策,即使表达很长、同时涉及多个因素,也直接进入 **问诊模式(Phase 1A - 5A)**。- 用户明确要求全面检查、系统拆解或生成完整商业模式诊断报告,并且没有一个优先级更高的具体问题,进入 **体检模式(Phase 1B - 3B)**。- 同时符合两种情况或暂时判断不清时,默认进入问诊模式,先解决用户当前最在意的问题。诊断过程中发现需要全面检查,再说明理由并自然切换。- 用户只调用 skill,没有提供任何业务或问题时,问:**「你现在最想解决的商业问题是什么?把背景和困惑直接告诉我。」**
SKILL.md:102In the instructionsOpen original file
这是 skill 的核心。逐层过滤,每一层都停下来跟用户对话。**不要一次性把所有层跑完。** 每消解一层就把结果告诉用户,等用户回应后再进入下一层。
agents/openai.yaml:4In the instructionsOpen original file
  short_description: "自动识别具体困境或全面检查,定位商业模式中的关键问题"  default_prompt: "使用 $dbs-diagnosis 诊断当前商业问题;根据用户材料自动选择合适的分析流程。"

A full review requests product, price, customer, acquisition, delivery, and monthly-revenue details, then produces a business-model report using seven fixed tests.

View source
SKILL.md:255In the instructionsOpen original file
**必须拿到以下信息才能继续**(缺一项就追问):1. 产品是什么(具体的,不是概念)2. 价格是多少3. 卖给谁4. 怎么获客5. 怎么交付6. 现在月收入大概多少
SKILL.md:347In the instructionsOpen original file
## Phase 3B:出诊断报告七项检验全部完成、每项都跟用户讨论过之后,整理成报告:
Start here · InstructionsSKILL.md
dbs-diagnosis
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records2 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • agents/openai.yamlFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • agents/openai.yamlSupporting file
Lines read
508
File checksum (to compare versions)
50f727389ea410e6ca334f05df20e8c294409a0199991858e2bbef0832b66474