Back to skill

Security audit

任务同频器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Chinese-language task handoff pack generator/verifier with disclosed file I/O and no evidence of hidden execution, exfiltration, persistence, or privilege escalation.

Install only if a Chinese-language task-package workflow fits your use case. Review the generated contract before sharing it, avoid putting secrets or full chat/customer data into the contract, and treat any permissions listed inside the package as notes that still require current user approval before real-world actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
node scripts/task-sync-pack.mjs build --input <任务合同.json> --out <任务名>.task-sync.zip

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
node scripts/verify-task-sync-pack.mjs <任务名>.task-sync.zip

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The display name, short description, and default prompt are all written in Chinese, which implies the skill is intended to operate in a specific language. The file does not indicate that language selection is optional or that the Chinese-only behavior is a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code enforces Chinese-specific filenames such as AI任务说明.md, 任务合同.json, and 任务说明.md, and throughout the file it emits only Chinese user-facing validation and usage text. For an all-file-types policy check, that is a locale/language restriction without user opt-in or an explicit documented justification in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese across the substantive changelog entries. The file does not state that the skill is intentionally region-specific or that language choice is user-selectable, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package description is entirely in Chinese, which can amount to a language/locale constraint in user-facing metadata without any indication that users can choose another language or that the package is intentionally region-specific. The keyword at L29 reinforces a Chinese-only positioning, but the manifest does not document that this is a locale-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script emits user-facing natural-language strings only in Chinese in both the usage message and error output. For a general-purpose verification script, this imposes a specific language without opt-in or any documented region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.