Back to skill

Security audit

pathway-score-guide-pro

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-focused education and career evaluation helper with local reference files and simple scripts, not a hidden installer or data-exfiltration tool.

Install only if you want a Chinese-language assistant for education or professional-title pathway estimates. Provide school, unit, and personal academic or employment details only when needed, and verify final decisions against current official institution documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
声明描述的是一个完整的升学/职称评估与指导系统,核心能力包括读取最新规则文件、按政策进行评分、输出差距分析、材料清单、时间线和建议。实际代码只包含一个非常轻量的 checklist 生成器:按 pathway 返回预设的若干月份/阶段事项,并原样输出 JSON。虽然输出内容与“时间线”这一子能力略有相关,但它只是静态模板,不涉及用户学校/单位规则、政策解析、评分或指导决策,因此与声明的主要用途存在明显且实质性的不匹配。

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
声明描述的是一个覆盖多场景、带政策依据和指导建议的综合评估与指引技能;而实际代码只是一个非常基础的评分引擎,根据输入的权重表和用户分数做求和并映射到等级。它没有检索或解析任何学校/单位文件,没有政策模板应用,没有分析用户与目标差距,也没有输出材料、时间线或建议。因此,代码行为仅覆盖了“评分”这一小部分,且还是静态权重加总,无法支撑声明中的主要用途,属于明显的描述与行为不匹配。

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The README is entirely written in Chinese and presents the skill as a general scoring and guidance assistant, but it does not state that Chinese is optional or that the skill is restricted to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The weak trigger phrases are broad enough to match ordinary educational or career-advice requests, which increases the chance of unintended routing into this skill. Misrouting can cause the assistant to collect unnecessary personal academic/employment information and provide overconfident pathway-specific guidance in contexts where the user did not ask for formal scoring, creating privacy and safety risks through inappropriate specialization.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file presents all output templates exclusively in Chinese and does not indicate that the user can select another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill is limited to a Chinese-speaking audience or that users can opt into another language. Under the natural-language policy category, forcing a specific language without opt-in is a locale-policy violation.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The listed weak triggers include generic phrases such as “帮我做路线规划” and “给我一个时间线,” which can appear in many everyday contexts unrelated to this skill’s intended domain. The file does not provide scope constraints or negative examples to clarify when these phrases should and should not activate routing.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The CSV template prepopulates the `pathway` field exclusively with Chinese-language values such as `保研`, `考研`, and `评职称`. Because this file provides no indication that the skill is China-specific or that users may choose another language/locale, it appears to impose a specific language by default.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The JSON values are entirely in Chinese, including the pathway and scoring dimensions, with no indication that the skill is region-specific or that users can choose another language. This can violate a language/locale policy when a skill implicitly requires a specific language without opt-in or documented justification.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The checklist pathways and outputs are defined entirely in Chinese string literals, which effectively forces a specific language/locale for users. There is no opt-in, fallback, or documentation in this file indicating that the skill is intentionally limited to Chinese-speaking users or a China-specific context.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This markdown file contains user-facing natural-language content entirely in Chinese, but does not indicate that the language is optional or limited to a specific locale. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy concern.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
This markdown file presents all user-facing guidance in a single language and does not indicate that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
All headings and trigger phrases are presented only in Chinese, which effectively enforces a specific language for users interacting with or maintaining the skill. The file does not indicate that the language restriction is optional, user-selected, or required for a clearly documented region-specific purpose.

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
The sample input schema and later output semantics are tied to Chinese-language field meanings such as 排名GPA, 英语, and Chinese grading labels, with no indication that users may choose another language or locale. This creates a natural-language locale policy issue because the skill appears to require a specific language by default rather than offering opt-in or documenting a region-specific justification.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The grade function always returns Chinese labels like 高, 中高, 中, 中低, and 低. Because the file provides no language selection or justification for a Chinese-only interface, this is a natural-language policy concern under the locale-choice rule.

Static analysis

No suspicious patterns detected.