Back to skill

Security audit

Table Specification

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-oriented educational exam-blueprint skill with some routing and language usability caveats, but no evidence of harmful access or hidden execution.

Install this if you want a structured Chinese-oriented workflow for creating exam specification tables. Be aware it may activate for broad exam-design prompts, and the package references supporting files that were not present in the inspected artifact, so some detailed examples or taxonomy guidance may be unavailable unless the publisher includes them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill declares extremely broad activation criteria, including generic requests like 'help me create an exam' and many overlapping keywords. In an agentic system, this can cause the skill to trigger when the user did not intend a blueprint workflow, leading to incorrect tool routing, unnecessary file access, and reduced reliability of downstream actions.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill metadata and content are written to operate in Chinese without offering a user-language choice, which can force outputs into an unintended locale. This is risky because users may misunderstand requirements, confirm the wrong workflow, or receive unusable output, especially in multilingual environments where precise educational specifications matter.

Static analysis

No suspicious patterns detected.