Natural-Language Policy Violations
- Category
- Not specified by scanner
- Confidence
- 83% confidence
- Finding
文件整体以中文撰写,且描述内容未说明这是面向中文用户的限定场景,也未提供用户可选择回复语言的选项。根据语言/地区策略,若技能隐含强制使用单一语言而未提供选择,可能构成自然语言政策违规。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a markdown-only startup workflow coaching skill with no executable code, persistence, credential use, or hidden data handling.
Installers should treat this as a lightweight Chinese-language product-process coaching skill. The main thing to watch is accidental activation from broad trigger wording; it does not appear to run code, access private data, or change the environment.
文件整体以中文撰写,且描述内容未说明这是面向中文用户的限定场景,也未提供用户可选择回复语言的选项。根据语言/地区策略,若技能隐含强制使用单一语言而未提供选择,可能构成自然语言政策违规。
The trigger list includes broad phrases such as '怎么开始' and '先手工做', which are common in ordinary product or planning conversations and can cause the skill to activate outside its intended scope. In an agent system, over-broad activation can inject irrelevant instructions into unrelated tasks, degrading reliability and potentially steering user workflows unexpectedly.
No suspicious patterns detected.