Back to skill

Security audit

data-insight-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese-language BI report generator that analyzes user-provided data snippets and does not request privileged access, persistence, network activity, or code execution.

Install this if a Chinese-language BI-style report format is acceptable. Redact personal, financial, or confidential fields before pasting data, because the skill is designed to analyze whatever sample rows the user provides.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill name, description, and usage guidance are presented entirely in Chinese, which creates a natural-language locale constraint. The file does not indicate that Chinese is optional, user-selectable, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example cases and validation rules strongly constrain outputs to Chinese-language phrasing and specific Chinese section headers without any indication that this is optional or user-configurable. In a general-purpose BI skill, this can override user preference, create prompt steering behavior, and cause reliability or policy-compliance issues when downstream systems expect locale-neutral or user-selected output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language metadata and parameter descriptions are entirely in Chinese, with no indication that language is selectable or that the skill is intended only for a Chinese-speaking or region-specific context. This can violate language/locale policy when a skill implicitly forces one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and user-facing instructions are written exclusively in Chinese, which can impose a fixed language on users without an explicit opt-in or locale justification. The policy requires flagging language or locale constraints when the skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-style JSON describes the skill's purpose in broad terms but does not define when the skill should or should not be invoked, nor does it provide specific trigger phrases or exclusion conditions. For manifest files, missing specificity around activation can lead to unintended invocation overlap with other general data-analysis requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.