Back to skill

Security audit

Meat-Protein凯氏定氮实验

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language lab guide and local calculator for Kjeldahl meat protein testing, with no hidden persistence, credential access, network retrieval, or destructive behavior found.

Install only if you are comfortable using a Chinese-language GB 5009.5-2025 Kjeldahl workflow. Treat it as procedural and calculation assistance, not a substitute for the official standard, validated lab SOPs, trained supervision, or chemical safety controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明将技能描述为覆盖凯氏定氮法检测“全流程”的指导工具,范围包括实验操作层面的试剂配制、消解、蒸馏、滴定及计算。但提供的代码仅是一个本地 CLI 计算脚本,接受用户输入的实验参数后进行公式计算、干基换算、平行样精密度判定和结果输出。它没有实现任何实验流程指导、步骤说明、操作检查、试剂配制逻辑或交互式教学内容。因此,代码行为只覆盖声明中的“结果计算/精密度验证”部分,未实现其宣称的主要广泛用途,属于描述与实际行为的实质性不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill file is entirely written in Chinese from the title onward, with no indication that users may choose another language or that the locale restriction is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a natural-language policy issue because the file presents its functionality, help text, and operational messages in a single language with no opt-in or alternative locale. The policy allows fixed locale only when explicitly justified as region-specific, but the file does not state such a constraint or offer a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

These user-facing strings determine how users interact with the tool, and they enforce one locale throughout execution. Because no alternative language path or explicit justification is provided, this fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.