Back to skill

Security audit

weekly-report-hy

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only weekly report formatter with some privacy caveats, but no hidden execution, persistence, network use, or data exfiltration.

Install this if you want Chinese weekly-report drafting from your own work notes. Review generated reports before sending them, especially when the input includes customer names, amounts, internal project names, or personal data, because the skill defaults to preserving those details unless you ask for redaction.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes the tool as generating '中文周报' and consistently frames input and output as Chinese-only behavior. This is a language-policy constraint presented as mandatory behavior, with no indication that users can choose another language or opt in to Chinese output.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states the skill will be automatically invoked whenever the user mentions broad terms like '周报', '周总结', '工作汇报', or lists weekly work items, without meaningful trigger boundaries or explicit user confirmation. Overly broad auto-invocation can cause unintended routing of user content into this skill, leading to wrong-task execution, privacy overexposure of work details, or bypass of user intent when they only want casual discussion rather than structured report generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are very broad and include common phrases like '周报' and '本周工作', combined with wording such as '务必使用此技能'. This can cause the skill to activate in ambiguous contexts and override more appropriate handling, creating prompt-routing risk and reducing user control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is defined as always producing Chinese output without checking the user's preferred language or whether the conversation is in another language. This can lead to unwanted language forcing, mishandling multilingual contexts, and potentially exposing transformed content in a language the user did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to retain sensitive information exactly as provided and not redact it removes an important privacy safeguard. In a reporting skill, this increases the chance of propagating customer names, financial details, personal data, or internal identifiers into polished outputs that may be shared more broadly.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is an explicit instruction to reproduce sensitive user-provided details without redaction or masking. Because the skill rewrites and professionalizes content for distribution as a weekly report, it materially raises the risk of privacy leakage and unintended disclosure of confidential business information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description states the tool produces '中文周报' and emphasizes professional Chinese weekly reports, which imposes a specific language behavior in natural language. Under the policy, locale or language constraints should either be optional or clearly justified; this manifest does not indicate user choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.