Back to skill

Security audit

Deepmine_5.2

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly transparent Chinese Socratic coaching skill, but it needs Review because it can activate broadly and includes tax/legal risk analysis inside a general reflection tool.

Install only if you want a Chinese-language guided-questioning workflow that may ask multiple follow-up questions and structure your words into documents. Be especially careful when discussing tax, finance, legal compliance, criminal-risk, budgets, internal systems, or business operations; treat any risk labels as prompts for professional review, not as legal or tax advice. Consider narrowing activation to explicit requests before using it in a general-purpose agent.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file defines a domain-specific tax/legal risk extraction engine that materially changes the skill from Socratic self-reflection into regulated financial/compliance analysis. This creates a capability mismatch: users invoking a reflective coaching skill could instead receive authoritative-seeming tax, legal, and criminal-risk assessments, increasing the chance of unsafe advice, scope creep, and unauthorized handling of sensitive compliance matters.

Vague Triggers

High
Confidence
95% confidence
Finding
The changelog explicitly states that after copying the system prompt, the agent will 'automatically start' when the user sends any request content. That creates overbroad activation and raises the chance the skill will intercept ordinary conversation or unrelated tasks, causing unintended steering, privacy overcollection, or prompt-behavior conflicts with other skills. In context, this skill is designed to probe deeply and structure user statements, which makes accidental activation more risky than a passive formatting skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README states that sending any request content will automatically start the skill, which makes activation too broad and can cause the skill to take over unrelated conversations without clear user intent. In an agent environment, this increases the chance of prompt-routing mistakes, accidental disclosure of user content into the skill workflow, and bypass of safer or more appropriate handlers.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad everyday requests such as '帮我想清楚' and '我不知道该怎么办', which can match many normal conversations and cause the skill to activate when the user did not intend a constrained Socratic workflow. Over-broad activation can hijack unrelated interactions, suppress direct assistance, and create prompt-routing errors that degrade safety and reliability.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation guidance says to use the skill when users express indecision or ask for help clarifying, but only loosely excludes 'ordinary chat' or already-clear conclusions. That ambiguity leaves too much room for subjective routing, increasing the chance that the full questioning workflow is applied inappropriately and interferes with user intent or higher-priority safety behaviors.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The skill description and triggers are entirely Chinese-centric and do not state whether the skill can adapt to the user's language or requires Chinese for a justified reason. In multilingual environments, this can cause misrouting, reduced accessibility, and user confusion if the skill activates but constrains interaction to a language the user did not choose.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The instruction set hard-codes Chinese output without any language negotiation or documented locale requirement. While not directly a code-execution issue, this can cause misunderstanding of sensitive tax/compliance guidance, especially if the surrounding agent or user operates in another language, making already high-stakes advice easier to misinterpret.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The handler explicitly requires all output to follow a constrained format written in Chinese, without any indication that the user's language preference, locale, or accessibility needs are checked first. This can override user intent and cause unsafe or unusable interactions for users who expect another language, leading to misunderstanding of important guidance and degraded reliability across the skill.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill is explicitly authored in Chinese and requires JSON-only routing behavior based on Chinese-language control phrases, without any mechanism to detect or adapt to the user's language. This can cause unsafe or incorrect operation for non-Chinese users because control intents, relevance checks, and routing decisions may be missed or misinterpreted.

Vague Triggers

Medium
Confidence
88% confidence
Finding
场景三的触发示例包含“帮我做个方案”“梳理需求”等较宽泛表达,容易把普通求助或泛化思考误路由为方案生成流程。对一个会主导多轮追问、收集并结构化用户内容的技能来说,误触发会导致不必要的信息采集、输出模板错配,以及偏离用户真实意图。

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The template hard-codes Chinese headings and output structure without any mechanism to respect the user's language, locale, or accessibility needs. In a general-purpose agent skill, this can cause unintended disclosure, misunderstanding, or unusable outputs for users expecting another language, especially when the skill is meant to preserve and restructure the user's own words.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The template hard-codes Chinese output and does not provide any mechanism to honor the user's preferred language or explain a necessary locale restriction. In an agent skill, this can cause misleading, unusable, or exclusionary output for users operating in other languages, and it may also interfere with downstream systems that expect language consistency with the user's input.

Static analysis

No suspicious patterns detected.