Back to skill

Security audit

三类主导模式判别器

Security checks for vulnerabilities and agentic risk

Overview

This is an advice-only Chinese Web3 classification skill with clear boundaries and no code execution, data access, persistence, or hidden authority.

Use this as a Chinese-language educational classifier for Web3 project model selection. Because it discusses financing, RWA, and legal boundaries, users should treat it as risk-identification guidance rather than legal, investment, or compliance advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown skill specifies its description and invocation cues entirely in Chinese, and later user-facing sections continue in that single language. Because the file does not offer an alternative language option or state that the skill is intentionally limited to Chinese-speaking users, it forces a locale/language choice without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The test cases and expected behaviors are written to require Chinese-language outputs, with no indication that the skill should preserve or adapt to the user's language. This can cause the agent to ignore user language preferences and reduce usability, accessibility, and policy compliance in multilingual deployments, though it is not a direct security compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is entirely written in Chinese and does not state that the skill supports multiple languages or that Chinese is a required, justified locale. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.