Back to skill

Security audit

Algorithm Learning Platform Builder | 算法学习平台构建助手

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent educational page-building skill, with the main cautions being third-party browser scripts in generated HTML and an unverified sample ZIP link.

Reasonable to install for algorithm education page generation. Review or replace the CDN script tags before publishing or sharing generated pages, avoid opening the sample ZIP unless you trust and inspect it, and adjust the template language if you need non-Chinese output defaults.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
assets/html-starter-template.html:8
Finding

Unpinned Third-Party JavaScript Is Retrieved and Executed at Runtime

Content
View full analysis
``` ### Technical Analysis The starter template loads Chart.js and MathJax directly from jsDelivr. Chart.js is not pinned to any version, while MathJax is constrained only to major version 3. Neither resource includes Subresource Integrity metadata. When a generated page is opened, the browser retrieves and executes the current resources returned by the CDN. The effective executable code can therefore change after the Skill package has been audited. A compromised package release, package account, CDN, or dependency-resolution path could inject arbitrary JavaScript into every page based on this template. Chart and mathematical rendering are legitimate requirements of the Skill. However, executing mutable remote code is not the minimum privilege necessary to provide those features; audited local copies or integrity-pinned resources can provide the same functionality with less supply-chain exposure. ### Attack Path 1. An attacker compromises a relevant package publication account, CDN delivery path, or mutable dependency resolution. 2. The attacker causes one of the referenced URLs to return modified JavaScript. 3. A user opens an educational HTML page generated from the starter template while network access is available. 4. The browser downloads and executes the modified script in the page context. 5. The malicious script can read or alter page content, capture datasets ...[truncated 771 chars]
Remediation
View remediation
``` 3. Prefer vendoring verified copies of Chart.js and MathJax into the Skill package when producing self-contained pages. 4. Record dependency versions and SHA-256 hashes in project documentation. 5. Add a restrictive Content Security Policy that permits scripts only from explicitly approved sources and blocks unexpected network connections. 6. Recalculate integrity hashes only after reviewing intentional dependency upgrades. 7. Provide an offline template variant that does not require runtime network access. ]]>

T08 · Insecure Dependencies

Note
Location
README.md:82
Finding

Externally Hosted Sample Archive Has No Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
- `references/request-routing-rules.md`
- `references/output-quality-checklist.md`

# Output rules

## For planning requests
Output should include:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · references/request-routing-rules.md (reported line 161)May include surrounding context.

md
- structured teaching content first if needed
- then full runnable html if requested

If the scope is complex, planning can still be brief, but do not refuse the full generation request.

---

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/writing-rules.md (reported line 8)May include surrounding context.

md
## Table of Contents
1. General writing rules
2. Teaching rules
3. Html output rules
4. Things to avoid

---

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/writing-rules.md (reported line 50)May include surrounding context.

md
---

## 3. Html Output Rules

When generating html:
- prefer a single-file html page

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The core skill description is presented entirely in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is unusually broad and includes generic triggers like planning, structuring, explaining, comparing, and generating educational content. In an agentic system that auto-selects skills from descriptions, this can cause the skill to be invoked for many unrelated education or explanation tasks, expanding its authority and increasing the chance that its internal instructions override a more appropriate, narrower skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file hard-codes trigger examples in Chinese and English as routing signals, but does not state that the skill is limited to those languages or provide a user language/locale choice. This can create a language-policy issue because behavior is implicitly tied to specific languages without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document sets lang="zh-CN", which imposes a specific language/locale in a reusable starter template. Because this is a generic 'Algorithm Learning Page' scaffold rather than a clearly region-specific tool, the fixed locale appears to violate the policy against forcing a language without user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template pulls executable JavaScript from third-party CDNs (jsDelivr for Chart.js and MathJax), which introduces a supply-chain and privacy risk if the CDN, dependency, or network path is compromised. In a starter scaffold intended to be reusable and possibly run locally, this expands trust beyond the local file and can enable arbitrary script execution in the page context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.