Back to skill

Security audit

Multi-Source Research - 多源研究

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed multi-source research helper with no bundled code, persistence, or hidden install behavior, though users should treat searches as external queries.

Install only if you want a Chinese-oriented research assistant that may query multiple external search, academic, social, and news platforms. Avoid submitting secrets, confidential project names, personal data, or sensitive research topics unless you are comfortable with those terms being sent to third-party services.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

Most of the visible instructions and usage examples are presented only in Chinese, and the skill name includes a Chinese assistant label, which can function as an implicit language constraint. There is no indication that other languages are supported or that the user can choose their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README advertises web, academic, social-media, and news aggregation without disclosing that user queries may be sent to multiple external services. This can create privacy and data-handling risk, especially if users submit sensitive research topics, internal project names, or personal data assuming the interaction is local.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README presents generic phrases like '研究一下 AI 发展趋势' and '找几篇关于机器学习的论文' as usage examples, but it does not define explicit trigger conditions, constraints, or non-trigger cases. These phrases are broad enough to overlap with ordinary user requests, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises querying multiple third-party platforms but does not warn users that their prompts, topics, or derived search terms may be sent to external services. Because the skill spans search engines, academic portals, social media, and news platforms, missing privacy disclosure materially increases the risk of exposing sensitive research interests or personal data across many recipients.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger condition is very broad: it activates for general research, information gathering, literature review, and public-opinion analysis without clear boundaries or explicit user consent checks. In a skill that queries many external sources, overly broad invocation increases the chance of unintended activation, unnecessary third-party requests, and accidental transmission of user queries to multiple platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The description and instructions are presented entirely in Chinese and focus on China-specific platforms such as 知网、微博、抖音、央视新闻、新华社 without indicating that users may choose another language or locale. This can be a natural-language policy issue if organizational policy requires offering language or locale choice rather than implicitly enforcing one default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.