Back to skill

Security audit

高等数学错题深度分析Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent calculus-learning helper, but it encourages use of identifiable student records and student profiles without privacy, consent, or retention guidance.

Review before installing in any real educational setting. Use anonymized or pseudonymous student data, avoid unnecessary names and identifiers, get appropriate consent, restrict access to generated profiles, and define retention/deletion practices before using it with actual student records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This feature goes beyond academic performance and analyzes psychological factors, motivation, self-efficacy, and student profiles without any explicit warning or handling restrictions. That makes the context more dangerous because it involves potentially sensitive inferences about minors or students, which can cause privacy harm, overprofiling, and misuse if shared or acted upon without consent and proper safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill documentation is entirely presented in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is explicitly designed to process student error records, learning patterns, and individualized educational analysis, but the description provides no privacy notice, data-handling constraints, or minimization guidance. In an educational context, this can lead users to submit identifiable or sensitive student data without informed consent or safeguards, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The personalized error book feature directly uses student_id, name, performance history, schedules, and learning-resource associations, yet includes no warning that these are sensitive student records. If deployed as documented, it could normalize storing or transmitting identifiable educational profiles, creating risk of unauthorized disclosure, profiling, or regulatory noncompliance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The tool definition for recommend_intervention_strategies says intervention_type must be one of immediate, short_term, or long_term (L191-L195), but the example invocation passes "comprehensive" (L328). This is an active contradiction between the documentation sections about how the tool should be used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.