Skip to content
Report library
Purpose / Other

Dbs Goal Skill Security Audit

What the author says it does (original text)

提取已有约束,只追问影响执行或验收的信息,把模糊愿望和目标整理成可行动、可检查的交付物。用户要求澄清目标、检查任务是否说清或定义交付结果时使用。

Independent security check

No obvious risks found in this check

Files checked
2
Risks found
0
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

8 instruction sections

The Skill’s actual behavior matches its stated purpose: it extracts the deliverable, audience, scope, specifications, completion criteria, and constraints from existing context, then decides whether the goal is actionable.

View source
SKILL.md:64In the instructionsOpen original file
先读取当前消息、此前对话、附件和用户已经确认的信息,再提取目标卡:| 字段 | 要提取的内容 || --- | --- || 交付物 | 要产生什么文件、结果、行为或状态 || 使用对象 | 谁会阅读、使用、购买或验收 || 范围 | 包含什么,排除什么 || 规格 | 格式、数量、质量、平台、时限 || 完成条件 | 出现什么证据即可结束 || 约束 | 时间、预算、资源、风险、禁区 || 后续用途 | 仅在它会改变当前方案时记录 |

When available information is sufficient, it instructs the agent to produce a concise goal card and stop questioning. When a blocking gap exists, it asks only one question per round that would materially affect the deliverable, execution path, or acceptance result.

View source
SKILL.md:82In the instructionsOpen original file
出现以下情况时直接放行:- 交付物清楚;- 下一步行动能够从上下文确定;- 完成条件能够从现有规格判断;- 剩余不确定性不会明显改变结果。输出简洁目标卡,标出必要假设,然后结束审计。不要为了走完流程继续提问。#### 路径 B:存在阻塞性缺口先告诉用户已经明确了什么,再找出信息增量最高的一个缺口。一次只问 1 个问题,等待回答后重新判断。阻塞性缺口必须满足以下条件之一:- 不同答案会产生不同交付物;- 不同答案会改变主要执行路径;- 不同答案会改变是否验收通过;- 擅自假设会带来明显返工、风险或价值偏离。

The Skill explicitly restricts the agent from deciding the audience, figures, deadlines, commercial purpose, or success criteria for the user, and requires safe assumptions to remain distinguishable from user-confirmed facts.

View source
SKILL.md:54In the instructionsOpen original file
### 4.保留用户主权保留用户原话、已给出的约束和取舍。可以提出候选表述,不能擅自替用户决定受众、数字、期限、商业目的或成功标准。
SKILL.md:294In the instructionsOpen original file
- 不用语法删词测试替代语义判断;- 不将模糊词直接替换成未经用户确认的数字;- 不把安全假设伪装成用户已经确认的事实;- 不预设固定的后续 Skill。

The supplied files contain only instructions and interface metadata; they provide no scripts, installation steps, network requests, credential access, file modification, or external-action instructions. This observation is limited to the fully listed source and does not establish that future versions are safe.

View source
agents/openai.yaml:1In the instructionsOpen original file
interface:  display_name: "dbs-goal"  short_description: "提取任务约束与验收标准,把模糊目标整理成可行动、可检查的交付物"  default_prompt: "使用 $dbs-goal,提取当前任务的约束与验收标准并明确交付物。"
SKILL.md:300In the instructionsOpen original file
完成当前任务后直接结束。只有用户明确询问下一步,且当前环境已经安装 `/dbs` 时,简短提示:「下一步不确定时,可以输入 `/dbs`。」
Start here · InstructionsSKILL.md
dbs-goal
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 1 more sections are available in the original file.
Files and check records2 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • agents/openai.yamlFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • agents/openai.yamlSupporting file
Lines read
311
File checksum (to compare versions)
a93216877d91936782a97fcccb375bd479a3c40f47a9cfbcd06be80178d7b225