Back to skill

Security audit

QBS Skill 拷问书籍方法论

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language workflow skill for turning book-based research into a new skill, with workspace writes and web/book retrieval that fit its stated purpose.

Install only if you want a Chinese-first research workflow that may create local qbs-runs outputs, update its library registry, and fetch or download book materials. Use authorized sources for any books and review generated child skills before installing or using them elsewhere.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description says the skill triggers when the user says the exact Chinese phrase "拷问书籍方法论", and the rest of the document presents the workflow entirely in Chinese without indicating that other languages are supported. This is a natural-language locale constraint that is not framed as optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states it will persist run artifacts under qbs-runs/<run-slug>/ and register generated skills in references/library.json, but it does not prominently warn the user or obtain consent before modifying the workspace. In an agent setting, silent file writes can create unexpected state changes, overwrite data, or leave sensitive research traces that users did not intend to store.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill explicitly directs the agent to download ebook files from public hosting without requiring a user-facing warning or explicit consent about copyright status, privacy exposure, or local storage of retrieved materials. Although it also says not to bypass access controls or purchase without authorization, it still normalizes acquisition and storage of copyrighted content in a way that can lead to unauthorized downloads, data retention, or compliance issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This file is a markdown skill reference, so natural-language policy checks apply. Nearly all operational guidance is written in Chinese, and the document does not state that the skill is region-specific or that users may choose another language, which can amount to forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction "领域关键词必须中英双语" imposes a fixed language requirement in natural-language policy, regardless of the user's stated language preference. This is a locale/language constraint and the document does not present it as optional or user-selected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON file contains natural-language content that forces a specific language context in the scope field. Under the policy, locale or language constraints should either be user-selectable or clearly justified as region-specific; neither is evident here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.