Back to skill

Security audit

ai-law-consultant

Security checks for vulnerabilities and agentic risk

Overview

This is a China-focused AI legal compliance reference and checklist skill with no hidden execution or data access, but users should verify current law before relying on it.

Install only if you need Chinese-language guidance on AI-related PRC compliance. Treat all outputs as checklists and legal education, verify current official sources before acting, and consult qualified counsel for enforcement exposure, litigation, penalties, or major business decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is explicitly scoped to Chinese AI law and presents itself as a legal compliance advisor, but the activation metadata does not clearly gate usage by jurisdiction or require confirmation that the user’s matter is China-related. This can cause users to receive authoritative-sounding legal guidance that is inapplicable to their locale, creating compliance, business, or legal risk through misleading omission rather than code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest sets language: zh-CN, and the surrounding description is entirely in Chinese, with no indication that users can choose another language or opt into this locale. Under the policy rule, a skill that enforces a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file presents the skill entirely in Chinese from the title onward, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill content is written only in Chinese, including operational guidance such as warning users and checking compliance red lines, with no indication that users may choose another language or that the skill is restricted to a China-specific audience. Under the stated policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script is branded and described as a compliance checking tool, but it does not collect or evaluate case-specific facts and instead prints static legal checklists. In a legal-compliance skill, this can mislead users into treating generic output as an actual assessment, causing incorrect business or personal compliance decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reported '合规状态' implies the tool has inspected the user's actual situation, but the result is derived solely from the presence of predefined high-risk checklist items. This is deceptive functionality: users may believe the tool found real violations or, in a modified version with no high-risk items, falsely believe they are compliant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses a single forced language throughout, beginning with the title, and does not provide any user opt-in, alternative language, or explanation that the guide is intended only for a Chinese-language audience. Under the policy, forcing a specific language without user choice can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file contains user-facing natural-language instructions and checklists solely in Chinese. Under the policy rule for language/locale constraints, forcing a single language without user opt-in or a clearly documented justification can be a policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The title and all subsequent instructional content are written only in Chinese, which effectively forces a specific language for users of this skill artifact. The file does not state that the skill is China-specific or offer any user language/locale choice, so it may violate organizational language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and includes language/locale policy violations. This script presents its title, usage, prompts, and output messages only in Chinese, which forces a specific language on users without opt-in or an explicit region-specific justification in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.