Back to skill

Security audit

meatpollutant牛羊肉罐头污染物超标判定

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language lab guide and calculator for Kjeldahl protein testing, with no hidden system, network, credential, or persistence behavior found.

Install this only if you need a GB 5009.5-2025-oriented Kjeldahl protein testing aid. Treat the lab procedure as reference material, not a substitute for institutional SOPs, SDS sheets, fume-hood requirements, PPE rules, and trained lab supervision.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

描述将技能定位为覆盖凯氏定氮法“全流程”的指导型能力,但代码仅是离线/命令行的计算与判定脚本,核心行为集中在公式计算、干基换算和精密度验证。虽然其中一部分与“计算蛋白质含量或验证精密度”相符,但对“指导畜禽肉蛋白质含量测定全流程,涵盖试剂配制、消解蒸馏、滴定操作”这一主要能力没有代码支撑,因此描述显著高于实际行为,构成描述与行为不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains the skill description, trigger conditions, and operating instructions entirely in Chinese, which effectively forces a specific language for users. The policy requires flagging language or locale constraints unless the skill explicitly offers user choice or documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This procedure gives detailed instructions for handling concentrated sulfuric acid, strong sodium hydroxide, heating digestion to high temperatures, and steam distillation, but it does not provide a dedicated, explicit safety warning section describing severe burn, splatter, inhalation, and pressure/boil-over hazards. In a skill intended to guide real-world lab execution, that omission materially increases the chance of user injury, especially for less experienced operators who may follow procedural steps without understanding the risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

A language or locale policy issue exists when a skill forces a specific language without user opt-in. This file presents all instructions exclusively in Chinese and does not indicate that the language choice is optional or that the skill is intentionally limited to a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to all file types and covers language/locale policy violations. The module docstring, CLI description, help text, and output strings are presented only in Chinese, which forces a specific language without offering users a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.