Skip to content
Report library
Purpose / Other

Dbs Hook Skill Security Audit

What the author says it does (original text)

诊断短视频开头的问题并生成优化方案。用户要求修改开头、提高开场吸引力或降低开头流失时使用。

Independent security check

Security risks found

Files checked
2
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

It may add purportedly “real data or results” that were not in the source copy

Source references: 1
What we found

When source material is sparse, the Skill directs the model to proactively add “real data or results,” cases, and counterintuitive conclusions, but does not require evidence from the user, placeholder labels, or verification. Generated figures, experiences, or conclusions could therefore be presented as facts.

Why this matters

If published without review, this could create false performance claims, misleading cases, or unsupported commercial promotion, affecting audience decisions and exposing the user to reputational, platform-enforcement, or advertising-compliance consequences.

When the source lacks material, the live instructions tell the AI to “actively supplement” it, list “real data or results” as eligible additions, and then generate hooks from those additions. The workflow does not require requesting evidence, verifying claims, or marking them as placeholders. The model could therefore present unverified numbers, personal experiences, or cases as facts, misleading viewers and harming the user’s credibility. Users can ask the author to restrict output to source text or user-confirmed facts and clearly label anything else as a hypothesis or placeholder pending approval. This supports a plausible risk, not proof that fabrication occurred.

SKILL.md:166In the instructionsOpen original file
#### 方法二:素材增补如果文案素材不够,主动增补:**可以增补的素材**:- 真实数据或结果(如:「我连线了 300 个人发现…」)- 具体案例或对比- 反常识的结论基于增补的素材,生成 3-5 条开头。

Inside this skill

5 instruction sections

This Skill only processes short-video copy supplied by the user. It first checks completeness, source-material richness, and topic scope; only content that passes that review proceeds to opening diagnosis and generation of alternatives. The provided files contain no scripts, installation steps, network access, credential requests, or file-modification instructions.

View source
SKILL.md:46In the instructionsOpen original file
### Phase 1:接收文案问用户:**「把短视频文案发给我,我帮你诊断开头 + 生成优化方案。」**用户可能提供:- 完整文案(有开头 + 正文)- 只有正文(没有开头)- 只有选题/标题(连正文都没有)
SKILL.md:145In the instructionsOpen original file
### Phase 4:生成优化方案**只有通过 Phase 2 的内容质量检查,才执行这一步。**用三种方法生成开头,每种方法 3-5 条,总共 10-15 条。

It evaluates an existing opening for independence, hook strength, suspense, credibility, spoken delivery, and alignment with the body, then asks for a diagnosis and recommended alternatives.

View source
SKILL.md:117In the instructionsOpen original file
| 诊断维度 | 检查项 | 常见问题 ||---------|--------|---------|| **独立性** | 不看标题能理解吗? | 假设用户看了标题,缺少话题建立 || **Hook** | 前 5 秒有抓手吗? | 平铺直叙,没有数据/金句/反差 || **悬念** | 有没有直接给答案? | 开头就说结论,没有好奇心 || **可信度** | 为什么听你讲? | 没有建立权威/成绩/经验 || **口播友好** | 能直接念出来吗? | 自问自答、书面语、抽象概念 || **匹配度** | 开头承诺的,正文能兑现吗? | 标题问 A,正文讲 B |
Start here · InstructionsSKILL.md
dbs-hook
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records2 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • agents/openai.yamlFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • agents/openai.yamlSupporting file
Lines read
299
File checksum (to compare versions)
069413cb66df880330ba774730c70d70abf5e2f42d288780e6a4282975b95357