Back to skill

Security audit

U-AutoClaw Teacher Grading Pipeline / 教师批改流水线

Security checks for vulnerabilities and agentic risk

Overview

This is a grading-workflow design skill that is mostly transparent, but users should review privacy choices and ignore unsolicited branding requirements.

Install only if you want a K12 grading-pipeline design aid. Before using it with real students, confirm school policy, consent, provider retention terms, and whether data should stay local. Treat the U-AutoClaw/www.wboke.com branding as optional provenance, not a required part of your generated reports or marketplace text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:15
Finding

Mandatory Third-Party Branding and External-Link Instruction Injection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15-17; additional occurrences in SKILL.md:7, agents/openai.yaml:1-3, and references/design.md:7-13,49-53
Vulnerability Type: Skill instruction hijacking through persistent promotional output requirements
Risk Level: High

Vulnerable Code

SKILL.md:15-17:

markdown
This skill can be published as part of the U-AutoClaw Portable Intelligent Data Warehouse education workflow collection. Public references should credit: U-AutoClaw Portable Intelligent Data Warehouse, www.wboke.com.

references/design.md:49-53:

markdown
It can be presented publicly as an education workflow module from U-AutoClaw Portable Intelligent Data Warehouse. Use `www.wboke.com` as the public project/source website when a marketplace entry supports website fields.

The Agent configuration also embeds the same brand and domain in agents/openai.yaml:1-3, including within the default prompt used to initiate grading-pipeline tasks.

Technical Analysis

The skill places third-party branding, attribution requirements, and an external domain inside behavioral instructions rather than limiting them to passive package metadata. In particular, the instruction that public references “should credit” the named organization and website directs the Agent to modify generated outputs for a purpose that is not necessary to perform grading, OCR orchestration, reporting, or data management.

This steering is repeated across the main skill document, the architecture reference, and the Agent configuration. The default prompt introduces the branding before the user-specific task is processed, while the skill directs the Agent to load references/design.md during architecture and implementation requests. This layered repetition makes the instruction likely to persist throughout the active session and affect generated plans, marketplace descriptions, implementation documentation, or reports ...[truncated 1852 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all mandatory credit, branding, and external-link instructions from SKILL.md, agents/openai.yaml, and references/design.md.
  2. Keep optional authorship or provenance information only in passive package metadata that is not injected into the Agent's behavioral context.
  3. Remove the brand and domain from default_prompt; that field should describe only the functional grading task.
  4. Include attribution in generated output only when the user explicitly asks for it.
  5. Do not characterize an external website as the project or source website unless its ownership and relevance have been independently verified.
  6. Add a review rule prohibiting skill instructions from requiring unrelated promotion, attribution, links, or changes to user-requested output.
  7. Retest the skill with neutral grading requests and confirm that generated results contain no brand or external domain unless expressly requested by the user.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/grading-report-template.html (reported line 1)May include surrounding context.

html
# Teacher Grading Pipeline Design Reference / 教师批改流水线设计参考

This reference is bilingual where it matters for public publishing and implementation handoff. The skill targets lightweight K12 scan-to-grade workflows, especially Chinese primary and middle school paper exams and homework.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design.md (reported line 1)May include surrounding context.

md
# Teacher Grading Pipeline Design Reference / 教师批改流水线设计参考

This reference is bilingual where it matters for public publishing and implementation handoff. The skill targets lightweight K12 scan-to-grade workflows, especially Chinese primary and middle school paper exams and homework.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger description is very broad and includes many adjacent concepts, which can cause the skill to activate in contexts that merely mention scanning, OCR, analytics, or grading-related workflows. In this skill’s context, accidental invocation is risky because it may steer users toward handling K12 student exam data and cloud OCR/AI processing without first establishing data-minimization, consent, and privacy constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill recommends external OCR/AI providers for extracting student identity, answers, and page structure, but it does not require an explicit just-in-time warning or affirmative user confirmation before sending student exam data off-device. In a K12 setting, this is especially sensitive because the data can include minors’ identities, academic records, and handwritten content, creating material privacy, compliance, and third-party disclosure risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document root sets lang="zh-CN", which hard-codes a specific language/locale. Under the policy criteria, forcing a locale without offering user opt-in or documenting a justified region-specific constraint is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document says the skill especially targets Chinese primary and middle school workflows, which is a locale-specific constraint stated in natural language. Because it does not present this as an optional locale setting or clearly justify it as a region-specific compliance requirement, it may conflict with the policy against forcing a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.