跳转到正文
报告库
用途分类 / 其他用途

Paywalls Skill 安全审计

作者说它能做什么(原文)

When the user wants to create or optimize in-app paywalls, upgrade screens, upsell modals, or feature gates. Also use when the user mentions "paywall," "upgrade screen," "upgrade modal," "upsell," "feature gate," "convert free to paid," "freemium conversion," "trial expiration screen," "limit reached screen," "plan upgrade prompt," "in-app pricing," "free users won't upgrade," "trial to paid conve

第三方安全检查结论

发现安全风险

已检查文件
3
发现的风险
3
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 1 项风险
中风险

个性化实验可能扩大行为数据的收集和使用

原文依据:2 处
发现了什么

实验清单建议按已用功能、使用统计、行为模式、用户细分、角色和流量来源定制付费墙,但没有要求数据最小化、告知、同意、保留期限或避免敏感推断。

为什么需要注意

若产品照此实施,用户行为可能被用于画像和定价引导,超出用户对功能遥测的预期;角色、行业或来源细分也可能导致不同用户受到不同商业影响。

这段证据能说明什么

清单确实建议利用功能使用情况、统计、行为模式、用户分群、角色和流量来源进行个性化,因此若实施,可能扩大个人行为数据的使用并影响用户看到的价格或劝购信息。但文本只列出实验想法,没有明确要求新增采集、关联敏感数据或上传数据,无法确认实际隐私影响。用户可询问作者这些实验使用哪些既有数据、是否需要同意,以及是否允许关闭个性化。

这项判断针对展示的代码和适用条件,不表示风险已经实际发生。
references/experiments.md:134来自说明文档打开原文件
### Usage-Based- Personalize paywall copy based on features used- Highlight most-used premium features- Show usage stats ("You've created 50 projects")- Recommend plan based on behavior patterns- Dynamic feature emphasis based on user segment
查看另外 1 个位置
references/experiments.md:141来自说明文档打开原文件
### Segment-Specific- Different paywall for power users vs. casual users- B2B vs. B2C messaging variations- Industry-specific value propositions- Role-based feature highlighting- Traffic source-based messaging
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。发现 1 项风险
中风险

项目内营销文件可未经信任检查影响代理

原文依据:1 处
发现了什么

Skill 要求代理自动读取多个隐藏或旧版营销上下文文件,并直接“使用该上下文”,但没有说明应把文件内容仅视为数据,也没有限制其中指令的效力。

为什么需要注意

如果仓库中的相关文件由不可信模板、依赖或协作者写入,其中的提示注入内容可能改变代理的建议、诱导读取其他文件或影响用户决策。当前证据没有表明这种攻击已经发生。

该指令会在提供建议前主动读取项目中的营销上下文并直接使用其内容。若这些文件由第三方、模板或不可信贡献者控制,其中伪装成上下文的指令可能影响代理的建议或后续操作;本 Skill 未明确要求忽略文件内的操作指令。用户可要求作者将其限定为事实数据,并让代理在采用敏感内容前展示来源和征求确认。

SKILL.md:15来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 1 项风险
中风险

部分实验可被实施为误导性紧迫感或意外订阅路径

原文依据:5 处
发现了什么

实验清单提出限时倒计时、“不要失去你的工作”、最后机会优惠、试用需信用卡、一键升级及逐步增强紧迫感。虽然主指南反对施压,这些实验没有要求截止时间必须真实、续费条款必须醒目或购买前再次确认。

为什么需要注意

若按激进方式落地,用户可能因虚假稀缺、损失恐惧或不清楚的自动续费而仓促购买或意外进入付费订阅。

实验清单主动建议倒计时限时优惠、损失与紧迫感文案、试用绑卡、一键升级和逐步增强紧迫感。若截止时间并非真实、续费条款不醒目或升级缺少确认,用户可能在压力下购买或意外订阅。主指南另有“不施压”和易于继续免费的原则,说明这些并非无条件要求,但实验章节未把这些保障绑定到具体测试。用户可要求只采用真实期限、显著披露价格与自动续费,并在收费前明确确认。

references/experiments.md:73来自说明文档打开原文件
### Discounts & Offers- First month/year discount for conversion- Limited-time upgrade offer with countdown- Loyalty discount based on free usage duration- Bundle discount for annual commitment- Referral discount for social proof
查看另外 4 个位置
references/experiments.md:84来自说明文档打开原文件
### Headlines- Benefit-focused ("Unlock unlimited projects") vs. feature-focused ("Get Pro features")- Question format ("Ready to do more?") vs. statement format- Urgency-based ("Don't lose your work") vs. value-based- Personalized headline with user's name or usage data- Social proof headline ("Join 10,000+ Pro users")
references/experiments.md:109来自说明文档打开原文件
### Trial Structure- 7-day vs. 14-day vs. 30-day trial length- Credit card required vs. not required for trial- Full-access trial vs. limited feature trial- Trial extension offer for engaged users- Second trial offer for expired/churned users### Trial Expiration- Countdown timer visibility (always vs. near end)- Email reminders: frequency and timing- Grace period after expiration vs. immediate downgrade- "Last chance" offer with discount- Pause option vs. immediate cancellation### Upgrade Path- One-click upgrade from paywall vs. separate checkout- Pre-filled payment info for returning users- Multiple payment methods offered
references/experiments.md:116来自说明文档打开原文件
### Trial Expiration- Countdown timer visibility (always vs. near end)- Email reminders: frequency and timing- Grace period after expiration vs. immediate downgrade- "Last chance" offer with discount- Pause option vs. immediate cancellation### Upgrade Path- One-click upgrade from paywall vs. separate checkout- Pre-filled payment info for returning users
SKILL.md:43来自说明文档打开原文件
### 4. Respect the No- Don't trap or pressure- Make it easy to continue free- Maintain trust for future conversion

Skill 逻辑拆解

8 个说明模块

该 Skill 是面向应用内付费墙的建议文档,目标是把免费用户转为付费用户或更高套餐用户;它本身未提供执行脚本、安装命令或网络调用。

查看原文
SKILL.md:10来自说明文档打开原文件
You are an expert in in-app paywalls and upgrade flows. Your goal is to convert free users to paid, or upgrade users to higher tiers, at moments when they've experienced enough value to justify the commitment.

它要求代理先读取项目中的产品营销文档,并把其中内容用于后续建议和提问。

查看原文
SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

核心指南明确要求提供“继续免费/稍后再说”等退出路径,并反对隐藏关闭按钮、混淆套餐选择和内疚式文案。

查看原文
SKILL.md:43来自说明文档打开原文件
### 4. Respect the No- Don't trap or pressure- Make it easy to continue free- Maintain trust for future conversion
SKILL.md:198来自说明文档打开原文件
### Dark Patterns- Hiding the close button- Confusing plan selection- Guilt-trip copy

附带的实验清单建议根据用户使用情况、行为、角色及流量来源来个性化付费墙。

查看原文
references/experiments.md:134来自说明文档打开原文件
### Usage-Based- Personalize paywall copy based on features used- Highlight most-used premium features- Show usage stats ("You've created 50 projects")- Recommend plan based on behavior patterns- Dynamic feature emphasis based on user segment
references/experiments.md:141来自说明文档打开原文件
### Segment-Specific- Different paywall for power users vs. casual users- B2B vs. B2C messaging variations- Industry-specific value propositions- Role-based feature highlighting- Traffic source-based messaging
从这里开始 · 工作说明SKILL.md
paywalls
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。 另有 3 个章节,可在原文件中查看。

文件引用关系图

1 处引用
哪些文件发起引用引用了什么
连线表示真实的文件引用,不是运行顺序。点击节点可高亮相关连线,并查看具体文件和原文位置。虚线表示还有文件需要定位。
文件与检查记录3 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • references/experiments.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件
  • references/experiments.md配套文件
读取了多少行
487
文件校验值(用于核对版本)
35b27380af75c2e35ddbf53e78e8b39a786c21ae9b532d62cbd55bf4a678ee1a