Back to skill

Security audit

软著撰写助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a document-preparation assistant for Chinese software copyright registration, with no executable code or hidden automation found.

Install only if you are preparing Chinese software copyright registration materials. Treat source code, IDs, licenses, signatures, and company seals as sensitive: provide only what is necessary, redact secrets from code, use the verified official portal, and avoid sharing scans through untrusted channels.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L164 states that all output must use Chinese, which imposes a fixed language policy on all users. The file does not provide an opt-in, alternative locale, or justification that the skill is restricted to Chinese-language users only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section instructs users to provide highly sensitive personal and corporate data, including identity numbers, addresses, contact details, business registration information, and signed/sealed documents, but gives no guidance on minimization, secure handling, retention, or redaction. In a skill designed to guide document preparation and submission, that omission can lead users to over-collect or insecurely store regulated data, increasing privacy, identity theft, and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow explicitly tells users to scan and upload application forms, identity materials, and supporting documents, but omits any warning about secure transmission, document sensitivity, phishing risk, or retention practices. Because these documents commonly contain personally identifiable information, signatures, seals, and corporate records, users may be exposed to data leakage or impersonation if they follow the steps without safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document title and all instructional content are written exclusively in Chinese, with no indication that language selection is optional or that the skill is limited to a Chinese-speaking or China-specific compliance context. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document title and all template instructions are written in Chinese, and the template provides no indication that language selection is optional or that the Chinese-only format is required for a specific regional or compliance context. This creates a natural-language policy concern because it effectively forces a locale/language without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/design-doc-template.md (reported line 154)May include surrounding context.

md
- 协议:HTTPS
- 数据格式:JSON
- 认证方式:{JWT Token / Session / API Key}
- 基础路径:{https://api.example.com/v1}

### 5.2 核心接口列表

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and formatting requirements prescribe Chinese-language conventions such as Chinese fonts and examples, and do not indicate that users may choose another language or locale. Under the policy, forcing a specific language/locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file presents all instructions and requirements only in Chinese, and there is no indication that the user can opt into another language or that the skill is restricted to a Chinese-speaking or China-specific audience. Under the policy rule for language or locale, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.