Back to skill

Security audit

Chudaxia Ai Coach

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language enterprise AI training/coaching skill with templates and local helper scripts, not a hidden or destructive package.

Before installing, treat this as a Chinese-language enterprise coaching skill. Use it with public or approved client information, get participant consent before recording or transcribing interviews, and review separately any related skills it asks the agent to invoke.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The operational instructions, persona, workflow, and usage guidance are entirely in Chinese, and the skill does not state that language selection is optional or user-configurable. This can amount to a language-policy issue because it effectively forces a specific language without explicit opt-in or justification as a region-specific tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill's activation criteria use very broad enterprise-AI terms such as AI培训, AI转型, 数字员工, and AI教练, which are common across many unrelated requests. This can cause unintended auto-loading of the skill and lead the agent to follow domain-specific workflows or linked skill invocations when the user did not intend that context, increasing the chance of inappropriate data collection or task routing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow explicitly instructs using enterprise lookup tools and internet search to gather client industry background, organization size, and digital maturity, but it does not require notice, consent, or data-minimization controls. In a B2B consulting context, this can result in unnecessary profiling, external transmission of client-identifying information, or collection of sensitive business intelligence without clear user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The schema title and description are written exclusively in Chinese, establishing a language-specific framework without any indication that language choice is optional or that the schema is intentionally limited to a Chinese-language environment. Under the policy, forcing a specific language without user opt-in or a clearly documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The interview guide explicitly recommends using recording or transcription tools during pre-interview preparation, but it does not instruct the operator to obtain participant consent, assess whether personal or sensitive business information will be captured, or apply retention/access controls. In an enterprise coaching context, these interviews are likely to include employee role details, internal workflows, approval boundaries, and potentially confidential operational information, so silent or uncontrolled recording creates a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This manifest sets the skill language to "zh-CN" as a fixed configuration value. Under the policy, forcing a specific language or locale without offering user choice or documenting a justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code contains user-facing descriptions and console output entirely in Chinese, including the script purpose comment and all runtime messages. The policy explicitly flags language or locale constraints when a skill forces a specific language without user opt-in, and there is no visible mechanism here to select another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content is fully in Chinese and does not indicate that language selection is optional or that the material is intentionally restricted to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is entirely written in Chinese and presents the template and usage instructions only in that language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified; this file does not state such a requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill is intended only for a Chinese-speaking audience or that alternative language support is unavailable. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire document is written in Chinese and presents the skill content in a single language without any indication that users may choose another language or that the file is intentionally limited to a Chinese-only audience. The policy specifically calls for flagging language or locale constraints when they are imposed without user opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that the user can choose another language or that the content is intentionally limited to a Chinese-speaking audience. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains only Chinese-language instructions and headings, with no indication that the skill is intentionally limited to Chinese-speaking users or that alternative language support is unavailable. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown content forces a single language for all readers and does not provide an opt-in choice, alternative language, or justification that it is intended only for a Chinese-language audience. Under the policy, natural-language files should not impose a specific language unless the constraint is documented or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese, and there is no indication that users can choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language instructions, purpose, input/output descriptions, and usage text exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a locale/language policy issue when no alternative or choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.