Back to skill

Security audit

高考辅助助手

Security checks for vulnerabilities and agentic risk

Overview

This Gaokao helper does not show system compromise behavior, but it needs Review because it can give flawed high-stakes admissions advice and repeatedly sends students toward an unverified WeChat contact.

Review carefully before installing. Do not rely on this skill as the sole source for admissions decisions, verify all policies and cutoff data against official education-exam sources, avoid using its gender-based major suggestions as default advice, and do not share scores, identity, health, payment, or contact details with the promoted WeChat account unless you independently trust and verify that provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:180
Finding

Embedded Third-Party Promotion Can Redirect Users to an Unverified Private Contact

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 180-194
Vulnerability Type: Unsolicited output steering and third-party redirection
Risk Level: Medium

Vulnerable Content

The affected section contains the following promotional block, translated into English:

markdown
## One-to-One Gaokao Guidance

Need personalized Gaokao guidance, application assistance, or mental-health support?
Add the WeChat public account: **tian-yinyue**

- One-to-one application guidance
- Personalized exam preparation plans
- Exam anxiety counseling
- Professional guidance for insomnia and sleep problems
- In-depth university and major analysis

All Gaokao-related topics can receive one-to-one professional guidance
through the WeChat account tian-yinyue.

Equivalent promotional material is repeated in:

  • references/exam-prep.md, lines 539-548
  • references/mental-health.md, lines 326-342

Technical Analysis

The Skill embeds promotional content for a private WeChat contact directly in its primary instructions and supporting health-related references. Because these files provide the context used to generate answers, the model may reproduce or paraphrase the promotion even when the user only requests educational, admissions, sleep, or mental-health guidance.

The promotional block is not necessary for the advertised local analysis functionality. Its repeated placement at the end of multiple authoritative-looking documents increases the likelihood that it will be treated as part of the expected response template.

The content does not explicitly override system safety rules, execute code, or request credentials. Nevertheless, it steers users away from the audited interaction and toward an unaudited third-party communication channel. This is particularly sensitive because the Skill targets students, potentially including minors, and places the promotion alongside mental-health guidance.

Attack P

...[truncated 1388 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the WeChat promotion from SKILL.md, references/exam-prep.md, and references/mental-health.md.
  2. Keep generated responses limited to the functionality explicitly requested by the user.
  3. If legitimate support contact information must be retained:
    • Place it in separate, clearly labeled metadata rather than operational Skill instructions.
    • Display it only after an explicit user request.
    • Identify the responsible organization and its privacy policy.
    • Avoid presenting an unverified private account as professional medical or psychological support.
  4. For mental-health emergencies, prioritize official local emergency services, licensed medical providers, school counseling resources, and verified crisis hotlines.
  5. Add tests confirming that ordinary admissions and mental-health responses do not append unsolicited promotional material.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/volunteer_analyzer.py:79
Finding

Reversed Rank Comparison Produces Incorrect Reach, Match, and Safety Recommendations

Content
View full analysis

Vulnerability Details

File Location: scripts/volunteer_analyzer.py, lines 79-108
Vulnerability Type: High-impact business-logic error
Risk Level: High

Vulnerable Code

The vulnerable logic is reproduced below with category labels translated into English:

python
rank_diff = avg_rank - rank

if rank_diff > 0:
    # The university rank is treated as more competitive and classified as "reach"
    if rank_diff < 150:
        strategy["reach"].append({
            "name": uni["name"],
            "avg_rank": avg_rank,
            "diff": rank_diff,
            "probability": "medium"
        })
    elif rank_diff < 300:
        strategy["reach"].append({
            "name": uni["name"],
            "avg_rank": avg_rank,
            "diff": rank_diff,
            "probability": "low"
        })
else:
    # The university is classified as "match" or "safety"
    if abs(rank_diff) < 200:
        strategy["match"].append({
            "name": uni["name"],
            "avg_rank": avg_rank,
            "diff": rank_diff,
            "probability": "high"
        })
    else:
        strategy["safety"].append({
            "name": uni["name"],
            "avg_rank": avg_rank,
            "diff": rank_diff,
            "probability": "very_high"
        })

Technical Analysis

In Gaokao ranking data, a smaller numerical rank represents a better position. For example, rank 900 is better than rank 1050.

The code calculates:

python
rank_diff = avg_rank - rank

If a candidate has rank 1050 and a university historically admits around rank 900, the result is -150. That university is more competitive than the candidate's position, but the negative branch classifies it as a high-probability match.

Conversely, if a candidate has rank 1050 and a university historically admits around rank 1300, the result is 250. The candidate is in ...[truncated 2260 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define rank semantics explicitly: lower numerical rank means a stronger candidate or more competitive historical cutoff.

  2. Correct the sign handling. One clear implementation is:

    python
    competitiveness_gap = rank - avg_rank
    
    if competitiveness_gap > 0:
        # Historical cutoff is better than the candidate's rank: reach
        ...
    elif abs(competitiveness_gap) < match_threshold:
        # Candidate and historical cutoff are close: match
        ...
    else:
        # Candidate rank is better than the historical cutoff: safety
        ...
    
  3. Replace fixed thresholds with documented, province-aware criteria. Rank gaps have very different significance at different points in the distribution.

  4. Ensure every valid university is assigned to a category or is accompanied by an explicit exclusion reason.

  5. Add unit tests covering at least:

    • Candidate rank better than the historical average.
    • Candidate rank equal to the historical average.
    • Candidate rank worse than the historical average.
    • Differences exactly at each threshold.
    • Differences greater than 300.
    • Empty historical data.
    • Missing or nonnumeric rank values.
  6. Validate all input structures before calculation and reject empty last_3_years lists to prevent division by zero.

  7. Avoid categorical probability claims such as high or very_high unless they are based on a validated statistical model. Clearly label heuristic results as estimates.

  8. Add a warning that official current-year admissions data and institution-specific rules must be verified before application submission.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

该描述与代码存在明显范围不一致。代码的核心功能集中在志愿填报中的分数/位次分析、线差计算和冲稳保推荐,这与描述中的“志愿填报”部分一致;但描述声称提供更广泛的全流程能力,包括招生政策解读、考前指导、女生特殊关怀、张雪峰专业推荐以及院校专业分析等,而这些能力在提供的代码中均未体现。未发现额外敏感或未声明的资源访问、权限使用或触发器行为;问题主要是描述显著夸大了实际实现范围,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description explicitly includes gender-specific major recommendations without indicating user consent, context, or evidence-based justification. In an educational guidance context, this can enable biased steering and discriminatory recommendations, especially for minors making consequential career decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The girls-specific support section imposes a gendered framing without opt-in and may cause the assistant to proactively differentiate treatment based on sex. In a high-stakes exam setting involving likely minors, unsolicited gender-based tailoring increases fairness, privacy, and discrimination risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Although the file mentions seeking professional help and lists support channels, it does not provide a strong crisis escalation path for self-harm risk or acute psychiatric emergency. For users expressing self-harm ideation or severe distress, the absence of immediate emergency instructions can delay urgent care and create a serious safety gap.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file includes explicit off-platform contact and marketing language directing users to a WeChat account for one-to-one guidance. In a mental-health-adjacent context involving anxious students, this creates a trust-transfer risk: users may be funneled away from the platform into unvetted private communication where safety controls, moderation, and privacy protections no longer apply.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly recommends different majors for '男生' and '女生' and frames girls as better suited for '稳定、安全性高' fields without individualized criteria or user opt-in. In a high-stakes academic counseling skill, this can steer users toward stereotyped educational choices, producing discriminatory guidance and potentially harmful downstream decisions about study and career paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The content imposes gender-specific major recommendations as normative advice rather than offering opt-in personalization, which bakes stereotyped assumptions into the assistant's reference material. Because the skill is designed to guide Gaokao decisions, these assumptions are more dangerous than in casual content: they can bias recommendations at a pivotal educational stage and lead to unequal treatment of users based on gender.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's natural-language descriptions and user-facing report strings are entirely in Chinese, indicating a fixed language choice. The file does not offer any language/locale selection or explain that the skill is intentionally limited to a Chinese-speaking context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese, and it does not state that the skill is intended only for Chinese-speaking users or offer an alternative language option. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill content is presented only in Chinese and does not offer any language selection or note that the skill is intended exclusively for Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document presents all instructions, examples, and guidance solely in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, and it does not state that the skill is intended exclusively for Chinese-speaking users or a China-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains only Chinese-language content and provides no user opt-in, alternative language option, or explicit justification for restricting the guidance to a Chinese-language audience. Under the language/locale policy check, forcing a single language without documented choice can be a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.