Back to skill

Security audit

Paper Defense Q&A + Code Audit + Visual Answer Cards

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate paper-defense purpose, but its helper scripts have unsafe path handling and its mandatory reply footer can override user-requested output formats.

Install only if you are comfortable with a skill that reads paper/project/code/training artifacts and writes generated defense-pack files. Do not run its Python helper scripts with untrusted --paper-slug values, on directories writable by other users, or as a privileged account; avoid packaging trees that may contain symlinks. Be aware that the skill may append fixed Chinese image-generation/status text unless your agent overrides that behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:147
Finding

Mandatory response suffixes hijack the agent's requested output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:147-152 and SKILL.md:846-853
Vulnerability Type: Agent response instruction hijacking
Risk Level: Medium

Vulnerable Code

markdown
At the end of every text-only delivery or textual response produced by this skill, append exactly this follow-up prompt as the final image-generation reminder. Do this after the written answer, while still keeping image generation as a separate follow-up step:

```text
请用chatgpt images 2.0 生成一系列 16:9 辅助答辩的插图,这些插图可以图文并茂的覆盖上面文字中的问题以及用生动的图表来解释回答,有助于更好准备答辩回答。
text

```markdown
## Reply footer rule

At the end of every substantive reply using this skill, append:

```text
Current Status
Recommended Next Skill
Possible User Inputs For Next Stage
text

The same mandatory image-generation instruction is reinforced in `workflow/08_visual_qa_storyboard.md:69-78`.

### Technical Analysis

These instructions unconditionally alter every textual or substantive response produced while the skill is active. They apply even when the user did not request images, a workflow handoff, or a status footer.

This is instruction hijacking because skill-level content overrides the user's requested response shape and injects unrelated content into the current session. The requirement to append the image-generation text “exactly” is particularly problematic for API clients that require strict JSON, XML, schema-constrained, or otherwise machine-readable output.

The image reminder also steers users toward a specific downstream service and model family. No hidden network request is made by the included scripts, but the response is nevertheless modified to promote an external follow-up action.

### Attack Path

1. The user asks a defense-related question that activates the skill.
2. The agent loads and follows `SKILL.md`.
3. The user requests a strict output format, a text-only answer, or an answer unrelated to image generation.
4.
...[truncated 649 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove all unconditional “append exactly” response requirements.

  • Only mention image generation when the user explicitly requests visual material.

  • Treat status footers as optional and subordinate to the user's requested format.

  • Add an explicit rule that user-specified schemas, formats, and language requirements take precedence.

  • Replace the mandatory instruction with conditional guidance, for example:

    markdown
    If the user explicitly requests a separate image-generation stage and has not
    specified an exact response schema, optionally provide a short vendor-neutral
    follow-up suggestion.
    
  • Avoid steering users toward a named provider unless they have selected that provider.

  • Add tests confirming that the skill produces valid JSON/XML without extra suffixes when such formats are requested.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/init_paper_defense_qa_scaffold.py:42
Finding

Explicit paper slug permits directory traversal during scaffold creation

Content
View full analysis

Vulnerability Details

File Location: scripts/init_paper_defense_qa_scaffold.py:42-50 and scripts/init_paper_defense_qa_scaffold.py:136-181
Vulnerability Type: Path traversal and file overwrite
Risk Level: High

Vulnerable Code

python
root = Path(args.root)
slug = args.paper_slug or slugify(args.paper_title)
defense_dir = root / "generated" / "defense" / slug
metadata_dir = root / "metadata"
reports_dir = root / "reports"

for directory in [defense_dir, metadata_dir, reports_dir]:
    directory.mkdir(parents=True, exist_ok=True)
python
for filename, content in markdown_files.items():
    write_text(defense_dir / filename, content)

qa_json = {
    "paper": {
        "paper_id": slug,
        "paper_title": args.paper_title,
        "paper_slug": slug,
        "venue": args.venue,
        "year": args.year,
        "subfield": ""
    },
    "generation_context": {
        "defense_context": "lab_meeting",
        "target_audience": ["advisor", "peer", "reviewer"],
        "input_artifacts": [],
        "missing_artifacts": [],
        "risk_tolerance": "conservative"
    },
    "qa_items": [],
    "evidence_gaps": [],
    "dangerous_questions": []
}
write_text(defense_dir / "defense_qa_bank_cn.json", json.dumps(qa_json, ensure_ascii=False, indent=2))

visual_storyboard = {
    "paper": {
        "paper_slug": slug,
        "paper_title": args.paper_title,
        "venue": args.venue,
        "year": args.year
    },
    "visual_policy": {
        "text_first_then_image": True,
        "target_environment": "chatgpt_web",
        "preferred_model": "Codex imagegen skill first when running inside Codex; otherwise ChatGPT Images 2.0 / gpt-image-2 when available",
        "style_brief": "clean academic infographic, PPT-friendly, consistent icon system",
        "aspect_ratio": "16:9",
        "exact_text_policy": "Use generated image
...[truncated 2654 chars]
Remediation
View remediation

Remediation Suggestions

  • Apply slugify() to explicit slugs as well as title-derived slugs.

  • Prefer a strict ASCII allowlist such as ^[a-z0-9][a-z0-9-]{0,127}$.

  • Reject . and .., path separators, absolute paths, empty values, and platform-specific separators.

  • Resolve and verify containment before creating or writing files:

    python
    base = (root / "generated" / "defense").resolve()
    slug = slugify(args.paper_slug or args.paper_title)
    defense_dir = (base / slug).resolve()
    
    if defense_dir.parent != base:
        raise SystemExit("Invalid paper slug")
    
  • Use exclusive creation or an explicit --overwrite option rather than silently overwriting existing artifacts.

  • Refuse to follow symlinks in destination components where the script may process untrusted directories.

  • Run the script with a minimally privileged account confined to a dedicated workspace.

  • Add tests for ../, absolute paths, mixed separators, Unicode separator lookalikes, and symlinked destination directories.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_visual_qa_prompt_pack.py:125
Finding

Visual prompt generator permits path traversal and external artifact overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_visual_qa_prompt_pack.py:125-140 and scripts/generate_visual_qa_prompt_pack.py:208-292
Vulnerability Type: Path traversal and file overwrite
Risk Level: High

Vulnerable Code

python
parser = argparse.ArgumentParser()
parser.add_argument("--root", default="paper_defense_bundle")
parser.add_argument("--paper-slug", required=True)
parser.add_argument("--max-cards", type=int, default=12)
parser.add_argument("--target-environment", default="chatgpt_web", choices=["chatgpt_web", "codex_cli", "api_pipeline", "manual_ppt"])
parser.add_argument("--preferred-model", default="Codex imagegen skill first when running inside Codex; otherwise ChatGPT Images 2.0 / gpt-image-2 when available")
parser.add_argument("--style", default="clean academic infographic, PPT-friendly, consistent icon system, high readability")
parser.add_argument("--aspect-ratio", default="16:9")
args = parser.parse_args()

root = Path(args.root)
defense_dir = root / "generated" / "defense" / args.paper_slug
qa_path = defense_dir / "defense_qa_bank_cn.json"
qa = read_json(qa_path)
python
write_text(defense_dir / "visual_qa_storyboard_cn.json", json.dumps(storyboard, ensure_ascii=False, indent=2))
write_text(defense_dir / "defense_qa_bank_cn.json", json.dumps(qa, ensure_ascii=False, indent=2))

# Additional Markdown generation omitted from this excerpt.

write_text(defense_dir / "visual_qa_storyboard_cn.md", "\n".join(md_lines) + "\n")
write_text(defense_dir / "visual_image_prompt_pack_cn.md", "\n".join(prompt_lines) + "\n")
write_text(defense_dir / "visual_generation_handoff_cn.md", handoff)
write_text(defense_dir / "visual_card_copy_cn.md", "\n".join(copy_lines))

Technical Analysis

The required --paper-slug is appended directly to a filesystem path without validation or canonical containment checks. Traversal segments can therefore redirect both t ...[truncated 1842 chars]

Remediation
View remediation

Remediation Suggestions

  • Validate --paper-slug using a strict lowercase ASCII slug expression.
  • Canonicalize the defense base and candidate path with Path.resolve().
  • Verify that the candidate is a direct child of the expected base before any read or write.
  • Reject symlinked defense directories when processing untrusted workspaces.
  • Open output files safely and require an explicit overwrite flag.
  • Keep input and output paths separately validated rather than assuming that a readable input makes the destination trusted.
  • Treat all QA-bank fields as untrusted when generating Markdown; escape or neutralize content that can act as agent instructions.
  • Add regression tests for traversal through both / and \, absolute paths, nested .., and symlink escapes.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_defense_qa_bundle.py:20
Finding

Bundle archiver follows file symlinks and can package files outside the selected root

Content
View full analysis

Vulnerability Details

File Location: scripts/build_defense_qa_bundle.py:20-29
Vulnerability Type: Symlink-based unintended file disclosure
Risk Level: Medium

Vulnerable Code

python
root = Path(args.root)
output = Path(args.output)
if not root.exists():
    raise SystemExit(f"Root does not exist: {root}")

with zipfile.ZipFile(output, "w", compression=zipfile.ZIP_DEFLATED) as zf:
    for path in sorted(root.rglob("*")):
        if path.is_file():
            zf.write(path, path.relative_to(root.parent if root.parent != Path("") else root))

Technical Analysis

Path.is_file() follows symbolic links. ZipFile.write() subsequently opens the referenced target and stores its contents in the archive. The script does not reject symlinks or verify that each resolved file remains under the resolved bundle root.

A file symlink located inside the bundle can therefore point to a readable file outside the bundle. The external target's contents are copied into the archive under the symlink's in-bundle name.

This is a confidentiality issue in environments where untrusted users can modify the bundle tree before a more privileged process packages it.

Attack Path

  1. An attacker can add files or symlinks beneath the bundle root.

  2. The attacker creates a symlink whose target is a sensitive file readable by the packaging process:

    bash
    ln -s /path/to/readable/secret /srv/job/bundle/reports/secret.txt
    
  3. A service account runs:

    bash
    python scripts/build_defense_qa_bundle.py \
      --root /srv/job/bundle \
      --output /srv/job/bundle.zip
    
  4. path.is_file() reports the symlink target as a file.

  5. zf.write() reads the external target.

  6. The resulting archive contains the target's contents as reports/secret.txt.

  7. The attacker retrieves or receives the generated archive.

Impact Assessment

The vulnerability can disclose any ...[truncated 485 chars]

Remediation
View remediation

Remediation Suggestions

  • Reject symbolic links explicitly:

    python
    if path.is_symlink():
        raise SystemExit(f"Symlinks are not allowed: {path}")
    
  • Resolve every candidate and verify containment under root.resolve() before archiving.

  • Require root.is_dir(), not merely root.exists().

  • Consider using os.open() with O_NOFOLLOW on supported platforms to reduce time-of-check/time-of-use races.

  • Package from an immutable or private staging directory not writable by untrusted users.

  • Add tests with file symlinks to external files, broken symlinks, and symlinks changed concurrently during packaging.

  • Generate and verify an explicit manifest of allowed regular files before creating the archive.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/package_clawhub_skill.py:78
Finding

ClawHub packager can follow symlinked files outside the skill directory

Content
View full analysis

Vulnerability Details

File Location: scripts/package_clawhub_skill.py:78-89 and scripts/package_clawhub_skill.py:143-149
Vulnerability Type: Symlink-based unintended file disclosure
Risk Level: Medium

Vulnerable Code

python
def iter_package_files(skill_dir: Path):
    for path in sorted(skill_dir.rglob("*")):
        if path.is_dir():
            continue
        rel = path.relative_to(skill_dir)
        if any(part in IGNORE_DIRS for part in rel.parts):
            continue
        if path.name in IGNORE_BASENAMES:
            continue
        if path.suffix.lower() in IGNORE_EXTS:
            continue
        yield path
python
def make_archive(skill_dir: Path, output: Path) -> None:
    if output.exists():
        output.unlink()
    with zipfile.ZipFile(output, "w", compression=zipfile.ZIP_DEFLATED) as zf:
        for path in iter_package_files(skill_dir):
            arcname = skill_dir.name + "/" + str(path.relative_to(skill_dir))
            zf.write(path, arcname)

Technical Analysis

The package iterator does not reject symbolic links or verify resolved-path containment. A symlink with an allowed text extension can pass the extension checks, while path.stat() during validation and ZipFile.write() during packaging follow the link to its external target.

For example, an in-tree symlink named notes.md can point to an arbitrary readable external file. The extension check examines the symlink's name rather than the target's actual type or location.

The package validation therefore does not prevent external files from being copied into the distributed .zip and .skill archives.

Attack Path

  1. An attacker can modify the skill directory before packaging.

  2. The attacker creates a symlink with an allowed extension:

    bash
    ln -s /path/to/readable/secret skill-dir/schemas/notes.md
    
  3. The validation process treats ` ...[truncated 795 chars]

Remediation
View remediation

Remediation Suggestions

  • Reject every symlink encountered by iter_package_files().
  • Compare each candidate's resolved path against skill_dir.resolve() using a robust containment check.
  • Inspect regular-file status without following links, such as through lstat().
  • Use no-follow file opening where available to reduce symlink-swap races.
  • Build packages from a clean checkout in a private, isolated directory.
  • Maintain an explicit allowlist or manifest of expected package paths.
  • Fail validation if any special filesystem object is encountered, including symlinks, sockets, devices, and named pipes.
  • Add CI tests proving that symlinked external files cannot pass validation or enter either archive.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill embeds instructions to validate metadata, inspect licensing, enforce file-type and size rules, and produce .zip/.skill archives, none of which are part of the user-facing defense-Q&A function. Such description-behavior mismatch is dangerous because it obscures non-obvious file operations and expands the effective attack surface beyond what a user would reasonably consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill embeds instructions to validate metadata, inspect licensing, enforce file-type and size rules, and produce .zip/.skill archives, none of which are part of the user-facing defense-Q&A function. Such description-behavior mismatch is dangerous because it obscures non-obvious file operations and expands the effective attack surface beyond what a user would reasonably consent to.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 844)May include surrounding context.

md
ill folder name URL-safe and lowercase: `paper-defense-qa-code-training`. Keep `SKILL.md` frontmatter with `name`, `description`, and semver `version`. Include

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The changelog includes a fixed Chinese-language prompt: 请用chatgpt images 2.0 生成..., which indicates the skill may direct generation in a specific language rather than offering a user choice. Per policy, forcing a language or locale without opt-in is a natural-language policy violation unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely written as a Chinese-only publishing instruction and includes a final image prompt in Chinese, with no indication that users may choose another language. Under the policy rule for natural-language violations, mandating a specific language without user opt-in is a reportable locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README hard-codes Chinese-language output filenames and describes outputs as Chinese-language artifacts, which can override or constrain the user's requested language without explicit consent. This is dangerous because it can cause the agent to ignore user preferences, reduce usability/accessibility, and create instruction-priority conflicts where skill behavior is steered by bundled documentation rather than the user's request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates appending a fixed Chinese follow-up prompt at the end of every text response for the image-generation workflow. This is risky because it injects unsolicited content into responses, forces a language choice without opt-in, and can manipulate downstream agent/tool behavior by embedding a required next-step prompt regardless of user intent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to read and write many files and to run local validation/packaging scripts, but it declares no explicit tool scope or permission boundaries. That increases the chance an agent with broader filesystem access will overreach, touching unrelated files or producing artifacts outside the intended workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction 'Use Chinese by default unless the user asks otherwise' establishes a default language policy that can override user expectations without prior opt-in. This matches the locale/language policy violation category because the skill imposes a specific language by default rather than explicitly eliciting the user's preference first.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template sets output_language to zh-CN, which imposes a specific language/locale by default. Under the policy, locale constraints should either be user-selectable or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The required fields include question_cn and answer_short_cn, and later optional fields include answer_long_cn, which structurally biases or mandates Chinese-language content. Under the policy, forcing a specific language without user choice or a clearly documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON template defines multiple required content fields specifically in Chinese, such as question_cn, answer_short_cn, and answer_long_cn, and includes Chinese-only instructional text. Because the file does not provide an alternative language option or explain that the template is intended only for a Chinese-language defense context, it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The contract fixes the main artifact path to defense_qa_bank_cn.md and provides the required report structure entirely in Chinese. This is a natural-language locale restriction, and the file does not offer opt-in language selection or explain why Chinese is required for a region-specific or compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is entirely framed as a Chinese style guide, including required user-facing text to append in Chinese, but it does not indicate that Chinese is optional or limited to a China-specific workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema requires multiple locale-specific fields suffixed with _cn, including title_cn, question_cn, spoken_answer_summary_cn, boundary_cn, visual_concept_cn, image_prompt_cn, and text_overlay_plan_cn. That imposes a specific language/locale on generated content, and the file does not provide any user choice or documented region-specific justification for the Chinese-only constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The field generation_reminder_cn provides an operational instruction only in Chinese, which can impose a language/locale constraint on users or downstream agents without opt-in. No alternative language option or justification for a Chinese-only workflow is present in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Across the generated filenames, field selections, markdown content, and prompt text, the workflow is fixed to Chinese (for example defense_qa_bank_cn.json, question_cn, and multiple Chinese prompt strings). This creates a natural-language policy concern because the skill forces a specific language/locale without opt-in or configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated focus specification sets output_language to zh-CN, which forces a specific locale by default. This is a natural-language policy concern because the script does not provide any opt-in, alternative language selection, or justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The scaffold requires and generates multiple _cn files and Chinese-language template content, indicating a fixed Chinese locale across outputs. Because the script provides no user choice or documented justification for this locale restriction, it violates the language-choice policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The validator requires filenames ending in _cn.md and section headings written in Chinese, which enforces a specific language/locale in skill behavior. In this code file, there is no natural-language indication that the language constraint is optional or justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow mixes Chinese-language output requirements into the skill without any indication that the user requested Chinese or that locale was negotiated. This can cause the agent to ignore user language preferences, degrade usability, and create misleading or inaccessible outputs in security- or defense-preparation contexts where precise communication matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill goal text explicitly instructs output in Chinese ("把论文里的所有主要 claim 转成可防守/不可防守的证据表") without any indication that the user's language preference was requested or that the task requires Chinese. This can override user intent, reduce usability, and cause incorrect or inaccessible responses for users expecting another language, though it is not a direct security exploit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes Chinese output ('从审稿人、导师、同领域 peer 和非专业听众视角生成论文层面的追问') without indicating that language should follow the user's preference. This can cause confusing or unusable responses for users expecting another language, and in a defense-preparation context may lead to incorrect presentation materials or reduce accessibility for reviewers and collaborators.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The goal line forces Chinese output ('把论文背后的代码、配置、训练流程、评估流程转成答辩问题和证据检查清单') without any indication that the user requested Chinese or that locale selection is intentional. This can cause unauthorized language switching, reduce usability, and create confusion or misinterpretation in a security- or evidence-sensitive workflow, especially when users expect answers in the conversation language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The goal text explicitly forces Chinese output ('把攻击面转成可直接背诵和可追溯证据的问答库') without any visible user opt-in, locale negotiation, or documented requirement that this workflow step must operate only in Chinese. In a defense-preparation skill, this can cause instruction-language mismatch, degrade usability, and lead to incorrect or inaccessible outputs for users expecting another language, especially when preparing evidence-sensitive answers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.