跳转到正文
报告库
用途分类 / 数据分析

Sales Enablement Skill 安全审计

作者说它能做什么(原文)

When the user wants to create sales collateral, pitch decks, one-pagers, objection handling docs, or demo scripts. Also use when the user mentions 'sales deck,' 'pitch deck,' 'one-pager,' 'leave-behind,' 'objection handling,' 'deal-specific ROI analysis,' 'demo script,' 'talk track,' 'sales playbook,' 'proposal template,' 'buyer persona card,' 'help my sales team,' 'sales materials,' or 'what shou

第三方安全检查结论

发现安全风险

已检查文件
6
发现的风险
1
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 1 项风险
中风险

本地产品营销资料可能被带入对外销售材料

原文依据:4 处
发现了什么

该 Skill 会在开始前主动读取隐藏配置目录或旧文件名下的产品营销文档,并要求在销售材料中使用该上下文。提案还被要求引用客户痛点和已接触的利益相关者。源文件没有要求在使用这些本地资料前区分公开信息与机密信息,也没有要求用户逐项批准。

为什么需要注意

如果本地上下文含有未公开定价、产品路线、客户名称、内部指标或联系人信息,这些内容可能出现在演示文稿、提案或单页材料中,并在用户后续发送给潜在客户时被披露。

该 Skill 的有效指令要求自动读取本地产品营销上下文,并在生成内容时使用它;提案定制还要求写入客户明确提到的痛点及已接触的利益相关者。若这些本地资料含内部定位、客户身份或交易细节,而生成物被发给潜在客户,就可能无意披露非公开信息。证据未显示必然泄露,也未规定公开性检查或逐项批准。用户可要求作者增加“仅使用获准公开的信息”、敏感字段脱敏及发送前确认。

SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
查看另外 3 个位置
SKILL.md:252来自说明文档打开原文件
- Mirror their language from discovery calls- Reference specific pain points they mentioned- Include only relevant case studies (same industry or use case)- Name the stakeholders you've spoken with
SKILL.md:250来自说明文档打开原文件
### Customization Guidance- Mirror their language from discovery calls- Reference specific pain points they mentioned- Include only relevant case studies (same industry or use case)- Name the stakeholders you've spoken with
SKILL.md:313来自说明文档打开原文件
## Output FormatDeliver the right format for each asset type:| Asset | Deliverable ||-------|-------------|| Sales deck | Slide-by-slide outline with headline, body copy, and speaker notes || One-pager | Full copy with layout guidance (visual hierarchy, sections) || Objection doc | Table format: objection, response, proof point, follow-up || Demo script | Scene-by-scene with timing, talk track, and interaction points || ROI calculator | Input fields, formulas, output display with sample data || Playbook | Structured document with table of contents and sections || Persona card | One-page card format per persona || Proposal | Section-by-section copy with customization notes |
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。未发现风险

Skill 逻辑拆解

8 个说明模块

该 Skill 用于生成销售演示文稿、单页材料、异议处理文档、演示脚本、ROI 计算器、销售手册和提案;提供的内容是 Markdown 指令与模板,没有显示自动发送材料、登录账户或执行脚本的步骤。

查看原文
SKILL.md:315来自说明文档打开原文件
Deliver the right format for each asset type:| Asset | Deliverable ||-------|-------------|| Sales deck | Slide-by-slide outline with headline, body copy, and speaker notes || One-pager | Full copy with layout guidance (visual hierarchy, sections) || Objection doc | Table format: objection, response, proof point, follow-up || Demo script | Scene-by-scene with timing, talk track, and interaction points || ROI calculator | Input fields, formulas, output display with sample data || Playbook | Structured document with table of contents and sections || Persona card | One-page card format per persona || Proposal | Section-by-section copy with customization notes |

它要求先读取项目中的产品营销上下文,再只询问尚未包含的信息。因此,生成结果可能结合用户没有在当前请求中重新提供的本地资料。

查看原文
SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

ROI 指导要求基于潜在客户输入或行业基准展示回报,并明确警告不要使用不现实、无法展示计算过程或与客户情况无关的数字。

查看原文
references/deck-frameworks.md:151来自说明文档打开原文件
**What to include:**- Expected return based on their inputs or industry benchmarks- Payback period- Total value over 1-3 years- Comparison to cost of inaction**What to avoid:**- Unrealistic projections- ROI without showing your math- Generic numbers not tied to their situation
从这里开始 · 工作说明SKILL.md
sales-enablement
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。 另有 7 个章节,可在原文件中查看。

文件引用关系图

4 处引用
哪些文件发起引用引用了什么
连线表示真实的文件引用,不是运行顺序。点击节点可高亮相关连线,并查看具体文件和原文位置。虚线表示还有文件需要定位。
文件与检查记录6 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • references/deck-frameworks.md已纳入全文
  • references/demo-scripts.md已纳入全文
  • references/objection-library.md已纳入全文
  • references/one-pager-templates.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件
  • references/deck-frameworks.md配套文件
  • references/demo-scripts.md配套文件
  • references/objection-library.md配套文件
  • references/one-pager-templates.md配套文件
读取了多少行
1,552
文件校验值(用于核对版本)
6ee45019d03b40c75ab8e13fd01d41e8dda5d0048173b3bad32ebe5aa9b0356b