Back to skill

Security audit

W-ABCD 真假 Web3 识别器

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Chinese Web3 project-evaluation skill with no code execution, persistence, credential access, or hidden installation behavior.

Install only if you want a Chinese-language checklist for Web3/RWA project authenticity and scam-risk review. For non-China jurisdictions, ask the agent to separate technical authenticity from local legal compliance and verify current rules with qualified sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger definition is broad enough to activate on ordinary trust/evaluation questions about projects, platforms, or exchanges, not just the narrowly intended W-ABCD/Web3-identification use case. Overbroad activation can cause the agent to force a specialized anti-scam/policy lens onto general queries, increasing the chance of misleading conclusions, unnecessary refusal-style behavior, or scope hijacking away from the user's actual request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The listed language-signal phrases include everyday wording like asking whether a platform or exchange is trustworthy, which can match many unrelated consumer or business questions. In an automated routing setting, this may misfire frequently and steer benign discussions into a highly specific fraud-detection workflow with strong assumptions, reducing answer quality and potentially introducing unjustified risk labels.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill applies a China-specific regulatory and policy framing as a default analytical lens without clearly limiting that framing to China-related contexts or offering the user a jurisdiction choice. For cross-border, non-China, or comparative queries, this can bias outputs, overstate illegality, and produce materially incorrect compliance or risk conclusions because legal treatment of tokens, exchanges, and RWA differs substantially by jurisdiction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file is entirely written as Chinese-only user-facing content and response guidance, with no indication that language should follow user preference or that alternative locales are supported. This can violate language/locale policy when the skill is used in broader contexts without explicit user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation trigger is broad and based on loosely defined phrases like '区块链就是 Web3' and '上了链', which can cause the skill to activate outside its intended scope. In a security-sensitive agent system, ambiguous routing can misclassify user intent, leading to incorrect advice, unnecessary escalation, or suppression of a more appropriate skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file content is entirely in Chinese and does not offer a language choice or document a locale restriction, which can exclude or mislead users who expect the skill to operate in other languages. In a security-sensitive due-diligence context, this can cause users to misunderstand criteria or outputs, increasing the chance of incorrect trust decisions rather than creating a direct exploit path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents all instructions and user-facing output in Chinese, but does not state that the skill is Chinese-only or provide any user language selection. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON file consistently defines prompts, expected behaviors, and notes only in Chinese, with no indication that language choice is optional or user-selected. Under the language/locale policy, a skill artifact that effectively constrains operation to a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.