Back to skill

Security audit

本命灵根测试

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language fantasy quiz skill whose local scripts support quiz generation and verification without hidden persistence, credential access, or data exfiltration.

Install this if you want a Simplified Chinese fantasy quiz and are comfortable with it generating a local HTML page and opening it in your default browser or HTML handler. In restricted environments, review or disable the auto-open workflow before use; the generated result code is shareable quiz output, not an authentication secret.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared user-facing purpose is a quiz, but the instructions also include local file generation, build/verification commands, and process launching behavior that is not clearly disclosed in the description. This mismatch can mislead users and reviewers about the real operational footprint of the skill, undermining informed consent and security review.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope, yet the content instructs the agent to read/write local files and execute shell commands. Without a least-privilege declaration, an integrating platform may grant broader capabilities than users expect, increasing the chance of unintended filesystem or process access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to generate a local HTML file and immediately open it via Start-Process or the system default handler. Spawning local processes and auto-opening content expands the attack surface beyond a simple quiz, and if the generated file or path handling is compromised, it could lead to unsafe content execution or unexpected application launches.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatically opening a generated HTML file without a user warning or consent prompt removes an important safety checkpoint. Even when the file is locally generated, launching it can surprise users, trigger external handlers, or expose them to rendered active content they did not explicitly agree to open.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction to keep a fixed '测灵人' tone and the entire skill content are written as if the interaction language is predetermined, with no opt-in or alternative language path. This can violate language/locale policy when the user has not chosen Chinese or this style explicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON manifest contains multiple user-facing strings and configuration values exclusively in Chinese, including stems, branches, banned terms, narrative opening text, and the disclaimer. Because the file does not indicate that the skill is region-specific or that users can opt into this locale, it appears to force a specific language, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON file contains all user-facing question and answer text exclusively in Chinese, with no indication that the skill is region-specific or that users can opt into a Chinese locale. Under the natural-language policy rule, forcing a specific language without user choice is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L45 requires the skill to avoid any modern vocabulary and present output only in a specific in-world style. This imposes a fixed language/locale/register behavior without user opt-in, which matches the policy category for natural-language constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file explicitly instructs operators to use real user distribution data to update calibration targets, but provides no accompanying requirements for consent, minimization, anonymization, retention, or access control. Even though this is only documentation, it can normalize unsafe handling of behavioral data and lead to privacy-sensitive analytics being collected or reused without proper safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code sets the document language to zh-CN and renders the page title and interface text in Chinese only. The policy specifically calls for flagging language or locale constraints when they are forced without user opt-in or a clearly documented, justified regional scope.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_quiz_html.py (reported line 249)May include surrounding context.

python
f.write(js)
            tmp = f.name
        try:
            proc = subprocess.run([NODE, "--check", tmp],
                                  capture_output=True, text=True, encoding="utf-8")
        finally:
            Path(tmp).unlink(missing_ok=True)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_quiz_html.py (reported line 296)May include surrounding context.

python
expects.append((res["talisman"], res["dao"]))
    cases_path = ROOT / "_verify_cases.json"
    cases_path.write_text(json.dumps(cases), encoding="utf-8")
    proc = subprocess.run(
        [NODE, str(ROOT / "scripts" / "verify_js.js"), str(DATA), str(cases_path)],
        capture_output=True, text=True, encoding="utf-8")
    cases_path.unlink()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file includes the module docstring and CLI usage/output text exclusively in Chinese, which effectively forces a specific language/locale on users. The policy allows locale constraints only when users are offered a choice or the restriction is explicitly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest promises question answering, root-type determination, post generation, and export of a reusable code. The documentation additionally assigns the agent responsibility for hidden state management such as randomly selecting a paper number, tracking prior answers, and controlling branching logic across turns; while related to implementation, this adds conversational stateful orchestration not stated in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This manifest-style JSON file contains all user-facing names and verse text in Chinese only, with no accompanying locale selection, fallback, or indication that the skill is intentionally region-specific. Because SQP-3 applies to all file types, this is a natural-language locale policy concern if the broader environment expects user choice rather than a fixed language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The HTML root sets lang="zh-CN", and all visible interface text is presented only in Simplified Chinese. Under the policy rule, forcing a specific language without user opt-in can be a natural-language locale violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a quiz that determines a user's spiritual root type, generates a themed post, and exports a code for reuse. In this file, the implementation also runs an external binary (node.exe) through subprocess.run to syntax-check/generated verify JavaScript, which is a development-time execution capability unrelated to the end-user testing purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.