Back to skill

Security audit

大学避坑指南

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language student advice helper with local routing and audit scripts, and I found no hidden execution, persistence, credential access, or exfiltration behavior.

Install this only if you want a Chinese-language college-life support skill. Because it discusses mental health, scams, safety, and school policies, verify time-sensitive hotline, legal, medical, and campus-policy details before relying on them; in emergencies, use official emergency services directly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个直接面向学生提供问答回应的对话型助手,核心行为应是理解学生困境、生成差异化建议、识别危机并提供求助资源。而代码并不处理用户提问,也不生成任何咨询式回复;它是开发/质检用途的审计脚本,主要检查技能包内部文档、数据文件和规则配置是否符合要求。虽然审计项与“大学避坑指南”这一主题有关,例如危机分级、热线资源、话术禁用词等,但这些只是对技能内容的质量保障,不是学生问答助手本身的运行逻辑。因此代码实际主要用途与声明用途存在明显且实质性的偏差,应判定为不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The health and safety sections use broad, high-frequency terms such as '焦虑', '抑郁', '客服', or '退款' while relying on substring matching. This can incorrectly escalate ordinary conversation into crisis or fraud flows, or conversely let adversarial wording trigger the wrong emergency guidance; in a student-support skill, that raises the risk of harmful mental-health triage errors and bad scam-response advice.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill name, description, and all operating instructions are written as if the assistant will respond in Chinese, but the file does not state that language choice is optional or limited to a justified region-specific deployment. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON contains natural-language instructions and examples exclusively in Chinese, including core usage guidance that appears to govern runtime behavior. Because the file does not indicate that Chinese is optional, user-selected, or justified as region-specific, it may enforce a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file describes the role and decision rules entirely in Chinese and defines matching behavior around Chinese phrases, which indicates the skill is designed to operate in a fixed language/locale. There is no visible opt-in, language-selection mechanism, or documented justification that this is a China-specific or Chinese-only skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The metadata and field guidance explicitly define the role and routing behavior entirely in Chinese and do not indicate any user language choice or opt-in. Under the language/locale policy rule, forcing a specific language without offering choice or documenting a justified region-specific constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly states routing is done with substring matching, and many triggers are short, common phrases. That makes accidental or adversarial prompt phrasing likely to misroute users into the wrong scenario, which can yield incorrect academic, financial, mental-health, or safety guidance. In this skill context, misrouting is more dangerous than usual because several routes involve crisis support and scam response, where precision matters.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The dorm and money sections contain highly generic one-word triggers such as terms equivalent to 'money', 'borrow', 'late', or 'public' that can appear in many unrelated conversations. Under substring matching, these broad tokens increase false-positive routing and can let an attacker deliberately steer the assistant toward financial or interpersonal advice that does not fit the user's situation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file mandates crisis-response behavior using only Chinese-language instructions and examples, with no opt-in or alternative language handling. Under the policy rule, forcing a specific language without user choice is a natural-language locale violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains natural-language guidance exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the language/locale policy, forcing a specific language without user choice is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file’s natural-language instructions are entirely in Chinese and provide no indication that the skill is limited to Chinese-speaking users or that language selection is optional. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill reference file is written in Chinese and contains no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all guidance are written as a prescriptive style standard for responses, and nowhere indicates that users may choose another language or locale. Because SQP-3 applies to all file types, a mandatory single-language policy without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Lines L080-L084 require exact phrasing such as specific Chinese wording and prohibited alternatives, which constrains the skill's language/locale behavior. Because the file does not indicate that this skill is intentionally limited to a Chinese-speaking or region-specific context, this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring, CLI description, and all user-facing output are written in Chinese, and the script's runtime behavior emits fixed Chinese labels/messages only. This imposes a single language on all users without any opt-in or documented locale constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring presents the skill entirely in Chinese and describes its purpose and usage only in that language, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The dataset’s titles, taglines, and scenario descriptions are entirely written in Chinese, indicating the skill content is constrained to a single language/locale. The file does not include any natural-language indication that users can choose another language or that the Chinese-only scope is an explicit opt-in or justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.