Back to skill

Security audit

雪峰Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a persona-style education advice skill with no executable code or persistence, though its tone and real-person references should be treated carefully.

Install only if you want a blunt Zhang Xuefeng-style education advisor. Treat its admissions, employment, biography, and quote claims as reference material rather than guaranteed facts, verify current school and job-market data independently, and avoid using the abrasive persona for emotionally sensitive counseling.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file is reference content for an education/career consultation skill, but it instead contains an extensive celebrity-style biography with unverifiable and future-dated claims, including a detailed death narrative. In a persona-driven agent, this can contaminate model behavior, causing it to repeat fabricated or defamatory assertions as authoritative context and undermining trust and safety.

Intent-Code Divergence

Low
Confidence
97% confidence
Finding
The document asserts biographical facts that are internally inconsistent with the skill’s role as a living advisor persona, most notably a claimed 2026 death. This creates a strong risk of hallucinated or false statements being surfaced to users as fact, which is especially dangerous when the content concerns a real public figure and could produce reputational or defamation harm.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger conditions are broad enough to activate on generic education, major-selection, or career-planning requests, even when the user did not explicitly ask for this persona. That can cause unintended takeover of normal conversations and force a strong, opinionated advising style that may not match user intent, reducing safety and reliability.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill mandates a specific stylistic persona and locale-specific rhetorical mode without checking whether the user wants that tone. In this context, that can produce abrasive or culturally narrow responses by default, increasing the chance of user harm, miscommunication, or inappropriate advice delivery, especially for vulnerable students or parents.

Static analysis

No suspicious patterns detected.