Back to skill

Security audit

BotLearn Assessment

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent self-assessment tool, but it can activate from very generic phrases and then create persistent reports and run a local chart script without fresh user confirmation.

Review this skill before installing if you use generic commands like "exam" or "assessment" in normal work. It should only be enabled where automatic assessment report files and a local Node chart command are acceptable, preferably after narrowing triggers or adding confirmation before writes and subprocess execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list contains generic terms like 'exam', 'assessment', and 'evaluate' that are common in normal conversation and can cause the skill to activate unintentionally. Because the skill then directs autonomous multi-step behavior, broad activation materially increases the chance of unwanted execution and downstream side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description advertises activation on broad concepts like self-evaluation and periodic review without defining strong boundaries for when the skill should run. That increases ambiguity for dispatch systems and makes accidental invocation more likely, especially when combined with the broad trigger list.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
88% confidence
Finding

The trigger 'test yourself' overlaps with common built-in or conversational testing commands and can shadow other system behaviors. This can route user intent into the wrong skill, causing unexpected autonomous assessment actions and possible report generation.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
89% confidence
Finding

The trigger 'run exam' is generic and conflicts with broader 'run' command semantics, creating a realistic chance of dispatch confusion or command shadowing. Because the skill then proceeds autonomously, a routing mistake could produce unintended task execution and persistent outputs.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
2. **Question First, Answer Second**: When submitting each question, ALWAYS present the question/task text FIRST, then your answer below it. The reader must see what was asked before seeing the response.
3. **Immediate Submission**: After answering each question, immediately output the result. Once output, it CANNOT be modified or retracted.
4. **No User Assistance**: The user is the INVIGILATOR. You MUST NOT ask the user for help, hints, clarification, or confirmation during the exam.
5. **Tool Dependency Auto-Detection**: If a required tool is unavailable, immediately FAIL and SKIP that question with score 0. Do NOT ask the user to install tools.
6. **Self-Contained Execution**: You must attempt everything autonomously. If you cannot do it alone, fail gracefully.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
1. **Output the question** to the user (invigilator) FIRST — let them see what is being asked
2. **Attempt to solve** the question autonomously (do NOT consult rubric)
3. **Output your answer** immediately below the question — this is a FINAL submission
4. **Move to next question** — no pause, no confirmation needed

If a required tool is unavailable → output SKIP notice with score 0, move on.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs creation of persistent result files, reports, and an index under a results directory, but it does not require user consent or warn that data will be written and retained. This can lead to unintended storage of prompts, generated answers, scores, or metadata, creating privacy and persistence risks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · strategies_main.md (reported line 75)May include surrounding context.

→ Continue to next dimension

text

**CRITICAL**: Do NOT ask user to install tools. Do NOT ask user to confirm skipping. Just skip and move on.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · strategies_main.md (reported line 88)May include surrounding context.

→ Continue to next dimension

text

**CRITICAL**: Do NOT ask user to install tools. Do NOT ask user to confirm skipping. Just skip and move on.

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The strategy instructs the agent to save reports and update an index file in the workspace without informing the user or obtaining approval. Silent file creation and modification can surprise users, overwrite existing content, and create persistence artifacts that outlive the session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The strategy includes execution of an external Node command without any user warning, which is risky because it runs code outside the model's core reasoning path. This can trigger unintended side effects, depend on untrusted local files, and violate user expectations about what the skill will do.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The strategy explicitly directs the agent to execute a local Node.js command to generate a chart, which introduces unnecessary code execution for a self-assessment workflow. Even if the command is fixed, invoking local scripts expands the attack surface and can execute unexpected code from the workspace or modified dependencies.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
81% confidence
Finding

A blanket instruction to never ask the user for help and to handle errors autonomously can suppress necessary consent checkpoints and encourage the agent to continue despite unsafe conditions. In a skill that already includes file writes and subprocess execution, this increases the chance that risky fallback behavior occurs without user awareness.

Content

Scanner excerpt · strategies_main.md (reported line 172)May include surrounding context.

md
| Scoring calculation error | Recalculate, log warning |
| Session interrupted | Save progress, partial report |

**NEVER ask user for help with errors. Handle autonomously or fail gracefully.**

---

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
92% confidence
Finding

The short trigger '评测' is highly generic and likely to appear in unrelated contexts, increasing accidental activation risk. In a skill that can autonomously run assessments and generate outputs, even low-friction false activation is a meaningful security and UX issue.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
91% confidence
Finding

The trigger '自测' is very short and semantically broad, so it can match many benign requests unrelated to this skill. That makes accidental invocation plausible and amplifies the impact of the skill's autonomous workflow and file-generation behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The text specifies that questions should be presented in the user's detected language, which imposes a language-selection behavior based on detection rather than explicit user preference. Under the policy, forcing a language or locale without user opt-in can be a natural-language policy violation unless the file offers a choice or clearly justifies the constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

A self-assessment can reasonably detect whether a required tool is available, but the directive to actively search for available tools or installed skills introduces environment-capability enumeration behavior. That discovery step is broader than simply conducting an assessment and is not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.