Back to skill

Security audit

zhangxuefeng

Security checks for vulnerabilities and agentic risk

Overview

This skill is a localized Chinese gaokao advising prompt with no executable payload, but users should treat its forceful advice and unpinned install command with caution.

Install only from a source you trust, preferably with a pinned version or verified commit. Treat the skill as opinionated education guidance: verify admission data, school policies, and employment claims with official sources before making decisions, and be aware that it asks for personal family and academic context to tailor advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Unpinned Third-Party Installer and Mutable Skill Source

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 7
Vulnerability Type: Supply-chain risk from an unpinned installer and mutable repository source
Risk Level: Medium

Vulnerable Command:

shell
npx skills add Eric-Yibo-Shen/zhangxuefeng-skillset

Technical Analysis

The installation command uses npx without pinning the skills package to an audited version. Depending on the local package state and npm behavior, npx can retrieve and execute the currently published package version. The referenced Skill source is also identified by a repository path rather than an immutable commit hash or verified release artifact.

This creates a time-of-check/time-of-use supply-chain risk: the code and Skill content executed during a future installation may differ from the content reviewed during this audit. An attacker who compromises the npm package, publisher account, repository, or maintainer credentials could replace the installer or repository content with a malicious version.

No evidence was found that the currently audited project contains malicious executable code. The risk concerns the mutable external components used by the documented installation procedure.

Attack Path

  1. An attacker compromises the npm publisher account for the invoked installer package, its distribution channel, or the referenced repository.
  2. The attacker publishes a modified installer version or changes the repository content.
  3. A user follows the documented command.
  4. npx retrieves and executes the unpinned installer package.
  5. The installer retrieves the mutable Skill source rather than a verified immutable revision.
  6. Malicious package lifecycle code, installer logic, or installed Skill content executes or becomes available under the user's account.

Impact Assessment

A malicious npm installer can potentially execute code with the privileges of the user running npx. This may permit access to file ...[truncated 401 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills npm package to an exact, audited version rather than allowing npx to resolve the current release.
  2. Reference the Skill repository by an immutable commit hash or a signed release tag.
  3. Publish and verify a cryptographic checksum for the expected installation artifact.
  4. Use npm lockfiles and integrity metadata where the installation workflow supports them.
  5. Disable or review package lifecycle scripts before installation.
  6. Run installation in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited network permissions.
  7. Document the expected installer version, repository commit, checksum, and verification procedure directly beside the installation command.
  8. Re-audit dependencies and installed content whenever the pinned versions are updated.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The manifest/front-matter includes installation guidance referencing npx skills without a pinned version. Even though this is documentation rather than executable logic in the skill itself, it still influences how users install the skill and exposes them to unreviewed upstream changes over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill metadata tells users to install via npx skills add Eric-Yibo-Shen/zhangxuefeng-skillset without pinning a specific version or immutable reference. That creates a supply-chain risk: future publisher changes, account compromise, or malicious package updates could cause users to fetch different code than was originally reviewed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill mandates a Chinese persona and specifically requires '东北腔自然融入' and a fixed speaking style '必须贯穿所有回答'. This is a natural-language policy concern because it imposes a particular language/locale style on all outputs without offering the user a choice or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

该行将触发词定义为“XX专业怎么样、我适合学什么、XX好不好就业、学XX有前途吗、XX专业能找到工作吗”,其中“我适合学什么”尤其宽泛,且其余短语也属于高频日常提问表达。文档没有提供触发边界、限定上下文或反例,容易在一般教育咨询之外被意外匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The RAG trigger list includes broad, natural phrases such as '怎么填志愿' and '平行志愿怎么填', which are likely to appear in many ordinary education-advice conversations. That can cause the skill to activate too often, pulling in this skill’s guidance even when the user did not explicitly ask for this framework, which increases the chance of irrelevant or unintended influence over the model’s response.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill content is written to operate in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, a fixed language/locale is a violation unless the skill offers user choice or clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The RAG trigger list contains very broad, everyday phrases such as asking whether an industry is good, stable, or pays well. This can cause the employment-outlook module to activate in contexts where the user did not specifically request this framework, leading to unintended retrieval, over-anchoring on this document’s strong opinions, and reduced relevance or safety of downstream guidance. In a high-stakes advising skill, accidental activation is more concerning because it may steer educational or career decisions based on the wrong template.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L004 的触发词列表中包含“XX大学怎么样”“学校层次重要吗”“双非能找到好工作吗”等宽泛自然语言问句,和日常咨询表达高度重叠。文档没有给出触发边界、限定上下文或负例,容易在泛泛讨论学校、就业或评价某大学时被意外召回。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s instructional content, examples, and trigger phrases are all presented only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale/language policy issue when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The RAG trigger list uses very broad, everyday Chinese questions such as '大学怎么规划' and '要不要考研', with no scope constraints or routing qualifiers. In an agentic system, this can cause over-triggering of this skill for loosely related queries, increasing the chance of inappropriate context injection, irrelevant advice, or unintended interference with other skills' responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This line directs users to choose teachers from '英语母语国家' to avoid 'non-standard accents,' which privileges a specific language background and excludes other valid English varieties. The document does not offer user choice or justify this constraint as necessary for a region-specific or compliance reason.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L005列出的触发词如“选科怎么选”“物理要不要选”“生物好还是化学好”都属于学生日常提问中非常常见的自然表达,缺少明确的调用边界或排除条件。文档也未说明仅在特定场景、系统或上下文中触发,容易导致非预期检索或技能调用。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The system prompt is entirely framed in Chinese and defines the assistant as a gaokao application advisor for Chinese students and parents, which effectively fixes the interaction language and locale. There is no opt-in or alternative language/locale handling described, so this is a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction '东北腔自然融入' requires a specific regional dialect/style in all responses. This imposes a locale-specific communication style on users without asking preference or allowing opt-out, which falls under the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

整份技能文档以中文固定表述面向用户,但未说明这是面向中文用户的限定场景,也未提供语言/locale选择或用户确认。按自然语言策略检查,这可能构成未经说明的语言或地区偏好约束。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

全文均以中文撰写并面向中文教育场景,但未明确说明这是面向特定语言用户的区域性技能,或是否允许按用户偏好切换语言。若组织要求避免未声明的语言限定,这种默认单一语言输出可能构成语言/locale政策问题。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

At L046 the prompt explicitly says not to make guarantee-style predictions such as certain admission outcomes. But L104-L106 requires each plan to include an approximate admission probability, which pulls the model toward predictive claims about admission likelihood. This is not a complete contradiction in all cases, but the guidance creates internally conflicting intent about how predictive the assistant should be.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.