Back to skill

Security audit

软考高级·系统规划与管理师论文模拟评分

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed exam-essay scoring skill with optional knowledge-base lookup and some low-impact branding/referral text, with no executable code or hidden persistence.

Installers should be aware that reports will include fixed author branding and a WeChat guidance referral. Use the optional IMA lookup only when you are comfortable sending search queries derived from the essay or topic to that knowledge-base integration.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill’s stated purpose is to simulate scoring of 系统规划与管理师 essays and provide improvement advice. L020 instructs users to contact a specific WeChat public account for one-to-one guidance, which is a marketing/referral capability rather than an obvious requirement of scoring functionality.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
L093-L098 require every report to append a fixed signature and a call to contact a specific公众号 for one-to-one guidance. This is not necessary to perform simulated grading or provide recommendations, so it introduces an unjustified branding/referral capability beyond the manifest’s described function.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The output format mandates a branded署名 and directs users to contact a specific WeChat account. This is not part of evaluating the essay against the 5-dimensional rubric and official 75-point conversion, so it exceeds the stated purpose of the skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation examples include generic phrases such as “打分”, “模拟阅卷”, and “论文质量评估”, which are broad enough to match ordinary conversation about evaluating writing rather than this specific exam-scoring skill. The README does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The README is entirely written as a Chinese-only skill experience and does not indicate that users may choose another language for interaction or output. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes generic phrases such as "打分", "质量评估", and especially "帮我看看论文过不过线 / 帮我批改论文", which are common requests outside this specific exam-scoring context. Although some lines mention the 系统规划与管理师 domain, the listed phrases are not consistently constrained, increasing the chance of accidental invocation.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The output format and all user-facing instructions are fixed in Chinese, and the skill does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless clearly justified as region-specific.

Natural-Language Policy Violations

Low
Confidence
87% confidence
Finding
The file's instructions, headings, and operational guidance are all presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The entire rubric is written in Chinese and targeted specifically to the Chinese '软考' exam context, with no indication that language selection is optional or that the skill can respond in other languages. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Static analysis

No suspicious patterns detected.