Back to skill

Security audit

DemandSpec

Security checks for vulnerabilities and agentic risk

Overview

DemandSpec is a coherent requirements-documentation skill that reads the workspace and writes requirement files as part of its stated purpose.

Install this when you want the agent to create or update requirement documents in your workspace. If you only want advice, say so explicitly, and specify the files or folders it should inspect if the repository contains unrelated sensitive material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the agent to write requirement assets into the workspace and says not to only respond in chat, but it provides no user-facing warning or confirmation step before modifying local files. In an agent setting, this can cause unexpected filesystem changes, accidental overwrites, or creation of large document trees when the user may have intended analysis-only assistance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary instruction text is written in Chinese and frames the skill behavior in that language, without indicating that users may choose another language. This can violate language/locale policy when a skill implicitly enforces a specific language absent user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The embedded CLI commands initialize projects and create new demand/change packages, which will create directories and files in the workspace without any built-in warning, preview, or consent checkpoint. If invoked automatically by an agent, this can lead to unauthorized repository mutations, clutter, or interference with existing project structure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default prompt instructs the agent to 'inspect the workspace' broadly whenever the skill is used, without narrowing scope to user-approved files or explicit requirement-analysis targets. In an agent setting, this can cause unnecessary exposure of unrelated repository contents, secrets, or sensitive documents and expands the blast radius of prompt injection or data over-collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire template is written as a required Chinese report format, and there is no indication that users may choose another language or that the template is intended only for a Chinese-language or region-specific context. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template is entirely written in Chinese, including the title and section headings, which imposes a specific language on users without any opt-in or alternative. The policy requires flagging language or locale constraints unless the skill offers user choice or clearly documents a justified region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown template uses Chinese headings and labels throughout, which imposes a specific language on users without any opt-in or indication that the skill is region-specific. Under the policy rule for natural-language violations, forcing a language/locale without user choice is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template is entirely written in Chinese and the generation instruction at L32 directs the model to produce output based on that Chinese-language specification, but it does not offer a language choice or note that the skill is intentionally region-specific. This can violate language/locale policy when users have not explicitly opted into Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template headings and field labels are entirely in Chinese, which imposes a specific language/locale by default. There is no indication that users may choose another language or that the template is limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains natural-language content exclusively in Chinese, which can impose a language choice on users without any visible opt-in or justification. Under the policy rule, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The short description is written only in Chinese, which can imply a fixed language/locale assumption for users without any opt-in or explanation. Under the language/locale policy, user-facing language constraints should either offer choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains natural-language instructions that assume a single language/locale for all users. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation unless the regional constraint is clearly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all template labels are written in Chinese, which imposes a specific language on users of the skill template. The policy allows locale constraints only when they are opt-in or clearly justified, neither of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file uses Chinese throughout the template, which can amount to a language/locale policy issue when the skill implicitly forces a specific language without user opt-in. There is no indication that the template is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown template uses Chinese throughout, including the title and field descriptions, with no indication that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy rule for language or locale, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown template presents all headings and field labels exclusively in Chinese, which can amount to a language/locale restriction in natural-language instructions. The file does not indicate that users may choose another language or that the Chinese-only format is a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire template is written as a fixed Chinese PRD format, with no indication that other languages are supported or that Chinese is required for a specific regional or compliance reason. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown template is written entirely in Chinese and does not offer any language or locale choice. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown template uses Chinese headings and field labels throughout, but does not state that the skill is intended only for Chinese-speaking users or offer any language choice. That can conflict with language/locale policy expectations when users have not explicitly opted into Chinese output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.