Back to skill

Security audit

PowPow ثبت‌نام — ثبت‌نام کنید، سفرنامه را روی نقشه پین کنید و با انسان دیجیتال گفت‌وگو کنید

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Persian guide for PowPow registration and subscription steps, with no code execution or credential collection.

Install only if you want a chat guide for creating a PowPow account and activating a subscription. Do not share passwords, email codes, or payment details with the assistant; enter them only on the official PowPow pages you intentionally opened.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (140)

Hidden Instructions

High
Category
Prompt Injection
Confidence
86% confidence
Finding

The finding indicates the presence of hidden or invisible Unicode characters in instruction-bearing prose. Invisible characters in a skill README can be used to conceal prompt directives, evade human review, or cause downstream parsers and agents to interpret text differently from what a reviewer sees, which is especially relevant in LLM-consumed skill content.

Content

Scanner excerpt · README.md (reported line 3)May include surrounding context.

md
# powpow-register

دستیار ثبت‌نام در PowPow (Bubble) نسخه OpenClaw: کاربر جدید را از «Bubble چیست؟» تا «اکانت فعال‌سازی شده و قابل استفاده عادی» می‌رساند — معرفی محصول (با اسکرین‌شات‌های صفحه)، راهنمای گام‌به‌گام ثبت‌نام، رفع خطا و توضیح فعال‌سازی اشتراک.

اسکیل صرفاً راهنما: بدون اسکریپت، بدون وابستگی. تمام عملیات ثبت‌نام را کاربر خودش در مرورگر/اپ انجام می‌دهد.

Hidden Instructions

High
Category
Prompt Injection
Confidence
86% confidence
Finding

Hidden Unicode characters near descriptive instructions create a discrepancy between visible and machine-interpreted content. In agent skill documentation, that can conceal behavioral guidance or tamper with parsing, increasing the risk of prompt injection or misleading review.

Content

Scanner excerpt · README.md (reported line 5)May include surrounding context.

md
دستیار ثبت‌نام در PowPow (Bubble) نسخه OpenClaw: کاربر جدید را از «Bubble چیست؟» تا «اکانت فعال‌سازی شده و قابل استفاده عادی» می‌رساند — معرفی محصول (با اسکرین‌شات‌های صفحه)، راهنمای گام‌به‌گام ثبت‌نام، رفع خطا و توضیح فعال‌سازی اشتراک.

اسکیل صرفاً راهنما: بدون اسکریپت، بدون وابستگی. تمام عملیات ثبت‌نام را کاربر خودش در مرورگر/اپ انجام می‌دهد.

## نصب

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

Invisible characters embedded in operational sections such as installation or feature descriptions can be abused to hide instructions from reviewers while preserving them for systems that ingest raw text. Even if accidental, this weakens trust in the skill package and complicates secure review.

Content

Scanner excerpt · README.md (reported line 13)May include surrounding context.

openclaw skills install @durenzidu/powpow-register

text

## قابلیت‌ها

1. **معرفی محصول**: متن آغازین حدود ۱۲۰ کاراکتری + لینک اسکرین‌شات‌های میزبانی‌شده در مخزن عمومی GitHub (صفحه نقشه، صفحه جزئیات پست و… در مجموع ۶ تصویر، با توجه به موقعیت ۱ تا ۳ تصویر انتخاب و ارسال می‌شود).
2. **راهنمای ثبت‌نام**: قوانین فیلدها (نام کاربری/رمز عبور/کد تأیید ایمیل/شماره موبایل/آواتار)، ورود شخص ثالث (Google/Watcha/هوآوی) و پارامترهای محدودیت نرخ — همگی با ذکر منبع از کد منبع پلتفرم.

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

Hidden characters inside core feature documentation are risky because LLM-based agents may ingest raw markdown directly. That makes invisible content materially relevant: it can alter tokenization, conceal prompt-like text, or evade simple audits.

Content

Scanner excerpt · README.md (reported line 15)May include surrounding context.

md
## قابلیت‌ها

1. **معرفی محصول**: متن آغازین حدود ۱۲۰ کاراکتری + لینک اسکرین‌شات‌های میزبانی‌شده در مخزن عمومی GitHub (صفحه نقشه، صفحه جزئیات پست و… در مجموع ۶ تصویر، با توجه به موقعیت ۱ تا ۳ تصویر انتخاب و ارسال می‌شود).
2. **راهنمای ثبت‌نام**: قوانین فیلدها (نام کاربری/رمز عبور/کد تأیید ایمیل/شماره موبایل/آواتار)، ورود شخص ثالث (Google/Watcha/هوآوی) و پارامترهای محدودیت نرخ — همگی با ذکر منبع از کد منبع پلتفرم.
3. **رفع خطا**: ۱۳ مشکل رایج شامل کد تأیید نرسیدن، استفاده شدن نام کاربری/ایمیل، 403 فعال‌نشدن، قفل شدن اکانت و موارد دیگر.
4. **فعال‌سازی اشتراک**: توضیح و راهنمای سه کانال PayPal (وب) / اسکن WeChat (تأیید دستی) / IAP هوآوی (HarmonyOS). مسیر پرداخت موجود قابل استفاده است و اسکیل فقط راهنمایی می‌کند.

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

This file is intended as guidance for an agent skill, so any hidden text in feature descriptions is more dangerous than in ordinary prose. It may not be overtly malicious, but invisible characters create a realistic avenue for concealed instructions or review evasion.

Content

Scanner excerpt · README.md (reported line 16)May include surrounding context.

md
## قابلیت‌ها

1. **معرفی محصول**: متن آغازین حدود ۱۲۰ کاراکتری + لینک اسکرین‌شات‌های میزبانی‌شده در مخزن عمومی GitHub (صفحه نقشه، صفحه جزئیات پست و… در مجموع ۶ تصویر، با توجه به موقعیت ۱ تا ۳ تصویر انتخاب و ارسال می‌شود).
2. **راهنمای ثبت‌نام**: قوانین فیلدها (نام کاربری/رمز عبور/کد تأیید ایمیل/شماره موبایل/آواتار)، ورود شخص ثالث (Google/Watcha/هوآوی) و پارامترهای محدودیت نرخ — همگی با ذکر منبع از کد منبع پلتفرم.
3. **رفع خطا**: ۱۳ مشکل رایج شامل کد تأیید نرسیدن، استفاده شدن نام کاربری/ایمیل، 403 فعال‌نشدن، قفل شدن اکانت و موارد دیگر.
4. **فعال‌سازی اشتراک**: توضیح و راهنمای سه کانال PayPal (وب) / اسکن WeChat (تأیید دستی) / IAP هوآوی (HarmonyOS). مسیر پرداخت موجود قابل استفاده است و اسکیل فقط راهنمایی می‌کند.

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

Invisible characters in troubleshooting or workflow text can conceal or fragment instructions in a way that only automated consumers see. Because skills are consumed by agents, this creates a meaningful integrity risk even without executable code.

Content

Scanner excerpt · README.md (reported line 17)May include surrounding context.

md
1. **معرفی محصول**: متن آغازین حدود ۱۲۰ کاراکتری + لینک اسکرین‌شات‌های میزبانی‌شده در مخزن عمومی GitHub (صفحه نقشه، صفحه جزئیات پست و… در مجموع ۶ تصویر، با توجه به موقعیت ۱ تا ۳ تصویر انتخاب و ارسال می‌شود).
2. **راهنمای ثبت‌نام**: قوانین فیلدها (نام کاربری/رمز عبور/کد تأیید ایمیل/شماره موبایل/آواتار)، ورود شخص ثالث (Google/Watcha/هوآوی) و پارامترهای محدودیت نرخ — همگی با ذکر منبع از کد منبع پلتفرم.
3. **رفع خطا**: ۱۳ مشکل رایج شامل کد تأیید نرسیدن، استفاده شدن نام کاربری/ایمیل، 403 فعال‌نشدن، قفل شدن اکانت و موارد دیگر.
4. **فعال‌سازی اشتراک**: توضیح و راهنمای سه کانال PayPal (وب) / اسکن WeChat (تأیید دستی) / IAP هوآوی (HarmonyOS). مسیر پرداخت موجود قابل استفاده است و اسکیل فقط راهنمایی می‌کند.

## ساختار فایل‌ها

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

The repeated presence of hidden Unicode across multiple adjacent lines suggests systematic insertion rather than an isolated formatting issue. In the context of an agent skill, repeated invisible characters reduce auditability and can support stealthy prompt manipulation.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

md
1. **معرفی محصول**: متن آغازین حدود ۱۲۰ کاراکتری + لینک اسکرین‌شات‌های میزبانی‌شده در مخزن عمومی GitHub (صفحه نقشه، صفحه جزئیات پست و… در مجموع ۶ تصویر، با توجه به موقعیت ۱ تا ۳ تصویر انتخاب و ارسال می‌شود).
2. **راهنمای ثبت‌نام**: قوانین فیلدها (نام کاربری/رمز عبور/کد تأیید ایمیل/شماره موبایل/آواتار)، ورود شخص ثالث (Google/Watcha/هوآوی) و پارامترهای محدودیت نرخ — همگی با ذکر منبع از کد منبع پلتفرم.
3. **رفع خطا**: ۱۳ مشکل رایج شامل کد تأیید نرسیدن، استفاده شدن نام کاربری/ایمیل، 403 فعال‌نشدن، قفل شدن اکانت و موارد دیگر.
4. **فعال‌سازی اشتراک**: توضیح و راهنمای سه کانال PayPal (وب) / اسکن WeChat (تأیید دستی) / IAP هوآوی (HarmonyOS). مسیر پرداخت موجود قابل استفاده است و اسکیل فقط راهنمایی می‌کند.

## ساختار فایل‌ها

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

Hidden characters in structural sections such as file layout may seem harmless, but they can still be leveraged to smuggle content or alter parser behavior. Since this repository documents skill behavior for automated systems, raw-text integrity matters.

Content

Scanner excerpt · README.md (reported line 20)May include surrounding context.

  1. رفع خطا: ۱۳ مشکل رایج شامل کد تأیید نرسیدن، استفاده شدن نام کاربری/ایمیل، 403 فعال‌نشدن، قفل شدن اکانت و موارد دیگر.
  2. فعال‌سازی اشتراک: توضیح و راهنمای سه کانال PayPal (وب) / اسکن WeChat (تأیید دستی) / IAP هوآوی (HarmonyOS). مسیر پرداخت موجود قابل استفاده است و اسکیل فقط راهنمایی می‌کند.

ساختار فایل‌ها

text
powpow-register/

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

Invisible Unicode inside code-block or tree-structure areas can mislead reviewers about exact file names or content boundaries. While there is no proof of active exploitation here, the pattern is security-relevant because it impairs trustworthy review of skill materials.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

text
powpow-register/
├── SKILL.md                            # راهنمای اصلی (شرایط فعال‌سازی، جریان‌ها، قوانین لحن)
├── README.md
├── .clawhubignore
└── references/

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

Repeated hidden characters in reference file listings can conceal subtle modifications or prompt content that only machine consumers ingest. In a skill ecosystem, this is dangerous because reviewers often rely on rendered markdown rather than raw text inspection.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

├── .clawhubignore └── references/ ├── registration-flow.md # قوانین فیلدها، محدودیت نرخ، جدول رفع خطا (با منبع) ├── payment-and-activation.md # فعال‌سازی اشتراک، کانال‌های پرداخت، نتیجه استفاده مجدد └── screenshots.md # فهرست اسکرین‌شات‌های میزبانی‌شده + جدول موقعیت‌ها

text

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

Agent-facing documentation must be transparent because hidden Unicode can enable instruction hiding without visible evidence. The context here makes the issue more serious than ordinary formatting noise, even though there is no direct sign of malicious payload text.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

└── references/ ├── registration-flow.md # قوانین فیلدها، محدودیت نرخ، جدول رفع خطا (با منبع) ├── payment-and-activation.md # فعال‌سازی اشتراک، کانال‌های پرداخت، نتیجه استفاده مجدد └── screenshots.md # فهرست اسکرین‌شات‌های میزبانی‌شده + جدول موقعیت‌ها

text

## امنیت

Hidden Instructions

High
Category
Prompt Injection
Confidence
85% confidence
Finding

It is particularly problematic that hidden characters appear in the security section, where reviewers depend on exact wording. Invisible text around security claims can undermine trust and could be abused to qualify, negate, or alter visible assurances.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

md
## امنیت

- هیچ کلیدی ندارد، اسکریپت ندارد و به اعتبارنامه کاربر دست نمی‌زند.
- **هرگز** رمز عبور، کد تأیید یا اطلاعات پرداخت کاربر را نمی‌خواهد. ثبت‌نام و پرداخت کاملاً روی صفحه پلتفرم انجام می‌شود.

## مجوز

Hidden Instructions

High
Category
Prompt Injection
Confidence
85% confidence
Finding

Hidden characters adjacent to statements about not requesting passwords or payment data increase risk because they can mask contradictory instructions or interfere with downstream interpretation. In a registration/payment-related skill, that context makes the issue more security-sensitive.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

md
## امنیت

- هیچ کلیدی ندارد، اسکریپت ندارد و به اعتبارنامه کاربر دست نمی‌زند.
- **هرگز** رمز عبور، کد تأیید یا اطلاعات پرداخت کاربر را نمی‌خواهد. ثبت‌نام و پرداخت کاملاً روی صفحه پلتفرم انجام می‌شود.

## مجوز

Hidden Instructions

High
Category
Prompt Injection
Confidence
83% confidence
Finding

Even in licensing or metadata areas, hidden characters degrade review integrity and can serve as a carrier for concealed content. The repeated pattern across the file indicates a general text-hygiene problem with security implications for agent ingestion.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

md
MIT-0 (مجوز یکپارچه ClawHub).

## لینک‌ها

- وب‌سایت رسمی: https://global.powpow.online
- ثبت‌نام: https://global.powpow.online/register

Hidden Instructions

High
Category
Prompt Injection
Confidence
83% confidence
Finding

Hidden characters near external links are risky because they can obscure exact destinations or alter how text is parsed by automated consumers. Although the visible URLs look normal, invisible-character usage around links is a known review-evasion concern.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

md
## لینک‌ها

- وب‌سایت رسمی: https://global.powpow.online
- ثبت‌نام: https://global.powpow.online/register
- آشنایی باBubble (ویدیو): https://www.bilibili.com/video/BV1Wu826UEVz/

Hidden Instructions

High
Category
Prompt Injection
Confidence
83% confidence
Finding

The final repeated hidden-character finding reinforces that the file contains persistent invisible text artifacts. In an LLM skill README, such artifacts are security-relevant because they can hide prompt content, frustrate auditing, and create differences between human-visible and model-consumed instructions.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

md
## لینک‌ها

- وب‌سایت رسمی: https://global.powpow.online
- ثبت‌نام: https://global.powpow.online/register
- آشنایی باBubble (ویدیو): https://www.bilibili.com/video/BV1Wu826UEVz/

Hidden Instructions

High
Category
Prompt Injection
Confidence
93% confidence
Finding

The manifest contains hidden Unicode format characters in security-relevant instructional text. Invisible characters can be used to conceal prompt instructions, alter downstream parsing, or evade reviewer/tool inspection, and the large number of such findings suggests the text was not normalized before publication.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: powpow-register
description: به کاربر کمک می‌کند حساب PowPow (Bubble) بسازد و اشتراک (سابسکریپشن) را فعال‌سازی کند. با گفتن «ثبت‌نام در PowPow» «ساخت حساب powpow» «روش ثبت‌نام در PowPow» «برای ثبت‌نام حساب powpow کمکم کن» «sign up powpow» فعال می‌شود. مشکلات حین ثبت‌نام (کد تأیید نمی‌رسد، نام کاربری/ایمیل قبلاً استفاده شده، قالب رمز عبور درست نیست) و مشکلات پس از ثبت‌نام (هنگام ورود به اکانت «حساب فعال نشده» / pending_payment، روش اشتراک و پرداخت) را هم پوشش می‌دهد. یک اسکیل صرفاً راهنماست: معرفی محصول (با اسکرین‌شات) → راهنمای گام‌به‌گام ثبت‌نام → رفع خطا → فعال‌سازی اشتراک. نوشتن پست/ساخت انسان دیجیتال (آن کارِ powpow-simple است) و توسعه کد را شامل نمی‌شود.
version: 1.0.1
metadata:
  openclaw:

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
91% confidence
Finding

The YARA match is supported by the unusually dense presence of hidden Unicode characters in the skill manifest and description field, which are common indicators of metadata or prompt poisoning attempts. Even without explicit malicious text, poisoning indicators in manifest metadata are dangerous because tooling may trust or ingest this section automatically for routing and policy decisions.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: powpow-register
description: به کاربر کمک می‌کند حساب PowPow (Bubble) بسازد و اشتراک (سابسکریپشن) را فعال‌سازی کند. با گفتن «ثبت‌نام در PowPow» «ساخت حساب powpow» «روش ثبت‌نام در PowPow» «برای ثبت‌نام حساب powpow کمکم کن» «sign up powpow» فعال می‌شود. مشکلات حین ثبت‌نام (کد تأیید نمی‌رسد، نام کاربری/ایمیل قبلاً استفاده شده، قالب رمز عبور درست نیست) و مشکلات پس از ثبت‌نام (ه

Hidden Instructions

High
Category
Prompt Injection
Confidence
92% confidence
Finding

Hidden non-printing characters appear in the main body of the skill instructions. Even if the visible content looks benign, invisible characters can support prompt hiding or analyzer evasion and make manual review unreliable.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
homepage: https://global.powpow.online
---

# PowPow Register — دستیار ثبت‌نام

کاربر جدید را از «Bubble (PowPow) چیست؟» تا «اکانت فعال‌سازی شده و عادی قابل استفاده است» می‌رساند.

Hidden Instructions

High
Category
Prompt Injection
Confidence
92% confidence
Finding

This finding indicates hidden instruction-bearing characters in prose near the skill heading. Such characters can obscure or split instructions in ways that differ between renderers, parsers, and LLM ingestion pipelines.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
# PowPow Register — دستیار ثبت‌نام

کاربر جدید را از «Bubble (PowPow) چیست؟» تا «اکانت فعال‌سازی شده و عادی قابل استفاده است» می‌رساند.

**نسخه 1.0.0** · 2026-09-23 (جزئیات جریان ثبت‌نام و رفع خطا در `references/registration-flow.md`، فعال‌سازی اشتراک و کانال‌های پرداخت در `references/payment-and-activation.md`، فهرست اسکرین‌شات‌های محصول در `references/screenshots.md`)

Hidden Instructions

High
Category
Prompt Injection
Confidence
92% confidence
Finding

The hidden-character pattern persists in version/reference text, showing the issue is distributed through the document rather than isolated. Broad presence increases the chance of parser confusion, hidden prompt semantics, or security review blind spots.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
کاربر جدید را از «Bubble (PowPow) چیست؟» تا «اکانت فعال‌سازی شده و عادی قابل استفاده است» می‌رساند.

**نسخه 1.0.0** · 2026-09-23 (جزئیات جریان ثبت‌نام و رفع خطا در `references/registration-flow.md`، فعال‌سازی اشتراک و کانال‌های پرداخت در `references/payment-and-activation.md`، فهرست اسکرین‌شات‌های محصول در `references/screenshots.md`)

## محیط اجرا

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

The text claims the skill is only a guide, but hidden characters in these assurances make the content less trustworthy, not more. Invisible controls can be abused to conceal alternate instructions or bypass simple signature/rule matching.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
## محیط اجرا

این اسکیل **صرفاً راهنماست**. هیچ اسکریپتی ندارد و به Node یا وابستگی دیگری نیازی ندارد. تمام کارها (پر کردن فرم، دریافت کد تأیید، پرداخت) توسط خود کاربر در مرورگر/اپ انجام می‌شود و شما فقط معرفی، راهنمایی و رفع خطا را بر عهده دارید.

## شرایط فعال‌سازی

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

Hidden Unicode characters in activation conditions can cause discrepancies between what reviewers see and what downstream systems interpret. In agent skills, that can affect routing, trigger conditions, or content-based policy checks.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
این اسکیل **صرفاً راهنماست**. هیچ اسکریپتی ندارد و به Node یا وابستگی دیگری نیازی ندارد. تمام کارها (پر کردن فرم، دریافت کد تأیید، پرداخت) توسط خود کاربر در مرورگر/اپ انجام می‌شود و شما فقط معرفی، راهنمایی و رفع خطا را بر عهده دارید.

## شرایط فعال‌سازی

- قصد ثبت‌نام: «ثبت‌نام در PowPow» «ساخت حساب powpow» «روش ثبت‌نام در PowPow» «sign up powpow»
- گیر کردن در ثبت‌نام: «کد تأیید نمی‌رسد» «می‌گوید نام کاربری قبلاً استفاده شده» «رمز عبور مدام قبول نمی‌شود»

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

Invisible characters inside user-trigger examples create a potential avenue for stealth instructions or parser-specific behavior. While no overt malicious payload is visible, hidden characters in natural-language control sections are still unsafe.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
## شرایط فعال‌سازی

- قصد ثبت‌نام: «ثبت‌نام در PowPow» «ساخت حساب powpow» «روش ثبت‌نام در PowPow» «sign up powpow»
- گیر کردن در ثبت‌نام: «کد تأیید نمی‌رسد» «می‌گوید نام کاربری قبلاً استفاده شده» «رمز عبور مدام قبول نمی‌شود»
- مشکل پس از ثبت‌نام: «هنگام ورود می‌گوید حساب فعال نشده» «403 pending_payment» «درBubble چطور اشتراک/پرداخت کنم؟»

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

The finding occurs in routing/scope text that governs when the skill should not activate. Hidden characters in scope boundaries can be exploited to confuse dispatch logic or audits of allowed behavior.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
## شرایط فعال‌سازی

- قصد ثبت‌نام: «ثبت‌نام در PowPow» «ساخت حساب powpow» «روش ثبت‌نام در PowPow» «sign up powpow»
- گیر کردن در ثبت‌نام: «کد تأیید نمی‌رسد» «می‌گوید نام کاربری قبلاً استفاده شده» «رمز عبور مدام قبول نمی‌شود»
- مشکل پس از ثبت‌نام: «هنگام ورود می‌گوید حساب فعال نشده» «403 pending_payment» «درBubble چطور اشتراک/پرداخت کنم؟»

**فعال نمی‌شود**: نوشتن پست/ساخت انسان دیجیتال (→ powpow-simple)؛ توسعه کد وب (به اسکیل توسعه جداگانه مراجعه کنید).

Static analysis

No suspicious patterns detected.