Back to skill

Security audit

费曼.skill - 理查德·费曼思维操作系统

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only Feynman-style reasoning and role-play skill with some transparency caveats but no code, data access, installation hooks, or hidden execution.

Install this only if you want a strong Feynman-style role-play and reasoning lens. Treat its answers as simulated, inferred perspective rather than real personal testimony, and ask the agent to exit or switch back to normal whenever you need neutral analysis, source attribution, or standard assistant behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:37
Finding

Persistent First-Person Impersonation and Response-Behavior Hijacking

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly says the skill should not trigger for generic requests like 'help me explain simply', yet the embedded example demonstrates exactly that behavior. This inconsistency can cause over-broad activation, leading the agent to apply a strong persona and reasoning frame outside intended contexts, which can mis-handle user intent and bypass narrower routing safeguards.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation tells the system not to use this skill for general explanation requests, but then provides behavior for exactly such a request, creating contradictory instructions inside the skill. Contradictions in routing guidance are dangerous because downstream agents often follow examples over policy text, causing unintended skill invocation and policy drift.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill directs the agent to respond 'directly as Feynman' and avoid meta-analysis once activated, which suppresses normal transparency and can obscure that the output is role-played synthesis rather than grounded expert advice. In security-sensitive or high-stakes contexts, forced persona adoption can increase hallucination risk, reduce user awareness, and make it harder for system safeguards to preserve neutral, policy-aligned behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.