Back to skill

Security audit

kechuang-collection

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently searches public Chinese government science-and-innovation sources and summarizes leads, with clear limits on sources, local files, credentials, and automation.

Installers should understand this is a China/Chinese government-source workflow. Do not put confidential company project names, personal data, credentials, or secrets into search keywords, and verify deadlines, eligibility, links, and amounts manually before acting on any lead.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire file is written in Chinese and presents source restrictions and operating instructions only in that language, with no indication that users may choose another language or that the skill is explicitly limited to a Chinese-only audience. Under the policy, forcing a specific language without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file's headings, command examples, output, and checklist are all written in Chinese, which effectively forces a specific language for users consuming this skill documentation. There is no indication that users can opt into another language, nor any documented justification that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes a skill focused on retrieving public government innovation information from a fixed whitelist, classifying it by KPI, and generating summaries for human review. This demo additionally documents persistent local file output, which is not mentioned in the description and is not strictly implied by 'generate summary' alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON mock data is entirely in Chinese, including priority labels, titles, summaries, and suggested actions, with no indication that the skill is region-specific or that users can opt into this locale. Under the policy rule for language/locale, a skill artifact that implicitly forces a specific language can be a natural-language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents all instructions, criteria, and matching rules exclusively in Chinese. Under the policy rule for language or locale constraints, forcing a single language without opt-in or justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains user-facing natural-language content such as titles, summaries, priorities, and suggested actions entirely in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation, and there is no indication here of language choice or justification for a locale-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.