Back to skill

Security audit

ZeeLin AI Detector

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language skill that estimates whether text sounds AI-written and does not request tools, credentials, persistence, or system access.

Install this if you want Chinese-language, style-based AI-writing estimates. Treat its percentages as rough opinions only, not as plagiarism results, academic integrity evidence, or output from a professional AI-detection service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s user-facing instructions are entirely in Chinese and provide no alternative language or indication that the skill is region-specific. This can violate a language/locale policy when users are not given a choice or informed of the locale constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger examples are broad natural-language phrases for a generic text-analysis task, which increases the chance that this skill is invoked when the user intended a different workflow. In a multi-skill environment, ambiguous activation can cause scope confusion, misleading outputs, or accidental interception of prompts better handled by another tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The specific trigger phrase 'AI查重' is ambiguous because it commonly refers to plagiarism or similarity checking rather than stylistic AI-generation estimation. This can misroute users into a skill that explicitly does not perform real database comparison, creating misleading expectations and incorrect task handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.