Back to skill

Security audit

合规边界红线检查

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only China-focused Web3 compliance checklist with no code execution, persistence, credential use, or hidden system changes.

Install only if you want guidance for mainland China Web3/tokenization risk triage. Treat its outputs as educational risk screening, not legal or investment advice, and verify current rules with qualified counsel or official regulatory sources before acting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is entirely in Chinese and scopes activation specifically to users operating in mainland China, with no indication that the skill can respond in other languages or that the locale restriction is optional. Under the policy rule, forcing a specific language or locale without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language content in the source metadata, prompts, expected behaviors, and notes is entirely in Chinese, which implies the skill is designed to operate in a specific language/locale. There is no visible opt-in, fallback, or statement that users may choose another language, so this can violate a language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses Chinese throughout, including headings, test cases, and recommendations, but does not mention that the skill is intended only for Chinese-speaking users or offer any opt-in for language selection. That can violate language/locale policy when a skill implicitly forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.