Back to skill

Security audit

用于快速产出**架构图 / 流程图 / 时序图 / 部署图**等可视化交付物,常见输出为 `.svg`(可离线打开)或 `.html`(浏览器直接预览)

Security checks for vulnerabilities and agentic risk

Overview

This diagramming skill is useful and mostly coherent, but its remote rendering and HTML preview paths can expose diagram contents or run mutable remote code without clear safeguards.

Use the pure SVG/offline mode for confidential diagrams. Before using Kroki, assume the full diagram source may be sent to the configured endpoint, verify KROKI_URL, and prefer a trusted private Kroki instance. Avoid opening generated HTML from untrusted diagram text or untrusted rendering endpoints, and pin/review Mermaid CLI instead of using the unpinned npx fallback.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_kroki.py:49
Finding

Unconditional Disclosure of Diagram Source to a Remote Rendering Service

Content
View full analysis
bytes: req = urllib.request.Request(url, data=body, method="POST") req.add_header("User-Agent", "Mozilla/5.0 (compatible; render_kroki/1.0)") for k, v in (headers or {}).items(): req.add_header(k, v) with urllib.request.urlopen(req, timeout=timeout) as resp: return resp.read() def render_via_kroki( diagram_type: str, output_format: str, source: str, kroki_url: str, *, use_json: bool = False, ) -> bytes: base = kroki_url.rstrip("/") if use_json: payload = json.dumps({ "diagram_source": source, "diagram_type": diagram_type, "output_format": output_format, }) return http_post( base + "/", payload.encode("utf-8"), headers={"Content-Type": "application/json"}, ) url = f"{base}/{diagram_type}/{output_format}" accept = FORMAT_ACCEPT.get(output_format, "") headers = {"Content-Type": "text/plain; charset=utf-8"} if accept: headers["Accept"] = accept return http_post(url, source.encode("utf-8"), headers=headers) ``` ```python parser.add_argument( "--kroki-url", default=os.environ.get("KROKI_URL", "https://kroki.io"), help="Kroki base URL", ) ``` ```python source = read_source(args.input_path) if output_format == "html": if diagram_type == "mermaid" and not args.json: html = mermaid_html_template(source, title=args.title) data = html.encode("utf-8") else: svg_bytes = render_via_kroki( diagram_type, "svg", source, ...[truncated 2822 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_kroki.py:87
Finding

Arbitrary Active-Content Injection in Generated HTML Diagrams

Content
View full analysis
str: svg = svg_bytes.decode("utf-8", errors="replace") return f""" {title} body{{margin:0;padding:16px;background:#fafafa;color:#222;font-family:system-ui, -apple-system, Segoe UI, Roboto, Arial, Helvetica, sans-serif}} {svg} """ def mermaid_html_template(mermaid_code: str, title: str = "Mermaid Diagram") -> str: escaped = mermaid_code return f""" {title} body{{margin:0;padding:16px;background:#fafafa;color:#222;font-family:system-ui,-apple-system,Segoe UI,Roboto,Arial,Helvetica,sans-serif}} .container{{max-width:1200px;margin:0 auto}} pre.mermaid{{background:#fff;border:1px solid #ddd;border-radius:8px;padding:16px;overflow:auto}}
text
{escaped}
    
""" ``` ```python if output_format == "html": if diagram_type == "mermaid" and not args.json: html = mermaid_html_template(source, title=args.title) data = html.encode("utf-8") else: svg_bytes = render_via_kroki( diagram_type, "svg", source, ...[truncated 3279 chars]
Remediation
View remediation
`. - Escape the document title. 2. Do not inline untrusted SVG responses directly into an HTML document. 3. Prefer storing the SVG separately and referencing it through an `` element. 4. If inline SVG is required, sanitize it with a strict allowlist that removes: - `

T08 · Insecure Dependencies

Warning
Location
SKILL.md:136
Finding

Unpinned Third-Party Code Is Downloaded and Executed

Content
View full analysis
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@10/dist/mermaid.esm.min.mjs'; mermaid.initialize({ startOnLoad: true, theme: 'default' }); ``` The same CDN import is emitted by `scripts/render_kroki.py`: ```python ``` ### Technical Analysis The documented fallback command invokes `npx` with automatic approval and without an exact package version: ```text npx -y @mermaid-js/mermaid-cli ``` This can download and execute whatever package version the registry resolves at invocation time. The effective code is therefore mutable after the Skill has been audited. Execution occurs with the invoking user's local privileges. The HTML template and generated Mermaid HTML also import executable JavaScript from jsDelivr. The dependency is pinned only to the broad major-version selector `@10`, not to an immutable version or verified artifact digest. No vendored copy, lockfile, or integrity verification is used. Because ECMAScript module imports do not use a Subresource Integrity attribute in this form, the browser relies entirely on the remote CDN and package resolution chain. A compromised upstream release, registry account, CDN, or dependency chain could therefore replace trusted rendering logic with hostile code. ### Attack Path #### Local `npx` path 1. The public Kroki service fails or returns a rate-limit respons ...[truncated 1419 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises direct local SVG generation with many styles and offline output, but the documented executable path heavily relies on external rendering via Kroki and also introduces undeclared formats and network behavior. This mismatch can mislead users about what code runs, what data leaves the environment, and what trust assumptions apply.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill advertises direct local SVG generation with many styles and offline output, but the documented executable path heavily relies on external rendering via Kroki and also introduces undeclared formats and network behavior. This mismatch can mislead users about what code runs, what data leaves the environment, and what trust assumptions apply.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/kroki-examples/ecommerce-microservices.svg (reported line 1)May include surrounding context.

text
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" contentStyleType="text/css" data-diagram-type="DESCRIPTION" height="1306px" preserveAspectRatio="none" style="width:1626px;height:1306px;background:#FFFFFF;" version="1.1" viewBox="0 0 1626 1306" width="1626px" zoomAndPan="magnify"><title>&#30005;&#21830;&#24494;&#26381;&#21153;&#24179;&#21488; - &#23481;&#22120;&#22270;</title><defs/><g><g class="title" data-source-line="5"><text fill="#000000" font-family="sans-serif" font-size="14" font-weight="bold" lengthAdjust="spacing" textLength="155.558" x="728.6244" y="22.9951">&#30005;&#21830;&#24494;&#26381;&#21153;&#24179;&#21488; - &#23481;&#22120;&#22270;</text></g><!--cluster sys--><g class="cluster" data-entity="sys" data-source-line="1593" data-uid="ent0004" id="cluster_sys"><rect fill="none" height="899.53" rx="2.5" ry="2.5" style="stroke:#444444;stroke-width:1;stroke-dasharray:7,7;" width="1466" x="7" y="242.2069"/><text fill="#444444" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="112.0002" x="683.9999" y="259.0584">&#30005;&#21830;&#24494;&#26381;&#21153;&#24179;&#21488;</text><text fill="#444444" font-family="sans-serif" font-size="12" font-weight="bold" lengthAdjust="spacing" textLength="59.4551" x="710.2725" y="273.9705">[system]</text></g><!--entity web--><g class="entity" data-entity="web" data-source-line="71" data-uid="ent0005" id="entity_web"><rect fill="#438DD5" height="101.4844" rx="2.5" ry="2.5" style="stroke:#3C7FC0;stroke-width:0.5;" width="215.9991" x="424" y="293.2069"/><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="39.9531" x="493.2378" y="318.0584">Web</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="5.5703" x="533.1909" y="318.0584">&#160;</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" leng
...[truncated 27 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/kroki-examples/ecommerce-microservices.svg (reported line 1)May include surrounding context.

text
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" contentStyleType="text/css" data-diagram-type="DESCRIPTION" height="1306px" preserveAspectRatio="none" style="width:1626px;height:1306px;background:#FFFFFF;" version="1.1" viewBox="0 0 1626 1306" width="1626px" zoomAndPan="magnify"><title>&#30005;&#21830;&#24494;&#26381;&#21153;&#24179;&#21488; - &#23481;&#22120;&#22270;</title><defs/><g><g class="title" data-source-line="5"><text fill="#000000" font-family="sans-serif" font-size="14" font-weight="bold" lengthAdjust="spacing" textLength="155.558" x="728.6244" y="22.9951">&#30005;&#21830;&#24494;&#26381;&#21153;&#24179;&#21488; - &#23481;&#22120;&#22270;</text></g><!--cluster sys--><g class="cluster" data-entity="sys" data-source-line="1593" data-uid="ent0004" id="cluster_sys"><rect fill="none" height="899.53" rx="2.5" ry="2.5" style="stroke:#444444;stroke-width:1;stroke-dasharray:7,7;" width="1466" x="7" y="242.2069"/><text fill="#444444" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="112.0002" x="683.9999" y="259.0584">&#30005;&#21830;&#24494;&#26381;&#21153;&#24179;&#21488;</text><text fill="#444444" font-family="sans-serif" font-size="12" font-weight="bold" lengthAdjust="spacing" textLength="59.4551" x="710.2725" y="273.9705">[system]</text></g><!--entity web--><g class="entity" data-entity="web" data-source-line="71" data-uid="ent0005" id="entity_web"><rect fill="#438DD5" height="101.4844" rx="2.5" ry="2.5" style="stroke:#3C7FC0;stroke-width:0.5;" width="215.9991" x="424" y="293.2069"/><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="39.9531" x="493.2378" y="318.0584">Web</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="5.5703" x="533.1909" y="318.0584">&#160;</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" leng
...[truncated 27 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/kroki-examples/online-ordering-c4.svg (reported line 1)May include surrounding context.

text
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" contentStyleType="text/css" data-diagram-type="DESCRIPTION" height="1323px" preserveAspectRatio="none" style="width:1607px;height:1323px;background:#FFFFFF;" version="1.1" viewBox="0 0 1607 1323" width="1607px" zoomAndPan="magnify"><title>&#22312;&#32447;&#28857;&#39184;&#31995;&#32479; - &#23481;&#22120;&#22270;</title><defs/><g><g class="title" data-source-line="5"><text fill="#000000" font-family="sans-serif" font-size="14" font-weight="bold" lengthAdjust="spacing" textLength="141.558" x="726.1243" y="22.9951">&#22312;&#32447;&#28857;&#39184;&#31995;&#32479; - &#23481;&#22120;&#22270;</text></g><!--cluster sys--><g class="cluster" data-entity="sys" data-source-line="1593" data-uid="ent0005" id="cluster_sys"><rect fill="none" height="915.83" rx="2.5" ry="2.5" style="stroke:#444444;stroke-width:1;stroke-dasharray:7,7;" width="1226" x="7" y="242.2069"/><text fill="#444444" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="96.0002" x="571.9999" y="259.0584">&#22312;&#32447;&#28857;&#39184;&#24179;&#21488;</text><text fill="#444444" font-family="sans-serif" font-size="12" font-weight="bold" lengthAdjust="spacing" textLength="59.4551" x="590.2725" y="273.9705">[system]</text></g><!--entity web--><g class="entity" data-entity="web" data-source-line="71" data-uid="ent0006" id="entity_web"><rect fill="#438DD5" height="101.4844" rx="2.5" ry="2.5" style="stroke:#3C7FC0;stroke-width:0.5;" width="215.9991" x="422" y="293.2069"/><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="39.9531" x="491.2378" y="318.0584">Web</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="5.5703" x="531.1909" y="318.0584">&#160;</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLe
...[truncated 28 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/kroki-examples/online-ordering-c4.svg (reported line 1)May include surrounding context.

text
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" contentStyleType="text/css" data-diagram-type="DESCRIPTION" height="1323px" preserveAspectRatio="none" style="width:1607px;height:1323px;background:#FFFFFF;" version="1.1" viewBox="0 0 1607 1323" width="1607px" zoomAndPan="magnify"><title>&#22312;&#32447;&#28857;&#39184;&#31995;&#32479; - &#23481;&#22120;&#22270;</title><defs/><g><g class="title" data-source-line="5"><text fill="#000000" font-family="sans-serif" font-size="14" font-weight="bold" lengthAdjust="spacing" textLength="141.558" x="726.1243" y="22.9951">&#22312;&#32447;&#28857;&#39184;&#31995;&#32479; - &#23481;&#22120;&#22270;</text></g><!--cluster sys--><g class="cluster" data-entity="sys" data-source-line="1593" data-uid="ent0005" id="cluster_sys"><rect fill="none" height="915.83" rx="2.5" ry="2.5" style="stroke:#444444;stroke-width:1;stroke-dasharray:7,7;" width="1226" x="7" y="242.2069"/><text fill="#444444" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="96.0002" x="571.9999" y="259.0584">&#22312;&#32447;&#28857;&#39184;&#24179;&#21488;</text><text fill="#444444" font-family="sans-serif" font-size="12" font-weight="bold" lengthAdjust="spacing" textLength="59.4551" x="590.2725" y="273.9705">[system]</text></g><!--entity web--><g class="entity" data-entity="web" data-source-line="71" data-uid="ent0006" id="entity_web"><rect fill="#438DD5" height="101.4844" rx="2.5" ry="2.5" style="stroke:#3C7FC0;stroke-width:0.5;" width="215.9991" x="422" y="293.2069"/><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="39.9531" x="491.2378" y="318.0584">Web</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLength="5.5703" x="531.1909" y="318.0584">&#160;</text><text fill="#FFFFFF" font-family="sans-serif" font-size="16" font-weight="bold" lengthAdjust="spacing" textLe
...[truncated 28 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/svg-layered-spec.md (reported line 16)May include surrounding context.

md
<?xml version="1.0" encoding="UTF-8"?>
<svg width="1000" height="700" xmlns="http://www.w3.org/2000/svg">
    <defs>
        <!-- 箭头标记 -->
        <marker id="arrowhead" markerWidth="6" markerHeight="5" refX="6" refY="2.5" orient="auto">
            <polygon points="0 0, 6 2.5, 0 5" fill="#94a3b8"/>
        </marker>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/svg-layered-spec.md (reported line 27)May include surrounding context.

架构图标题 ... ...

text

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/svg-layered-spec.md (reported line 27)May include surrounding context.

架构图标题 ... ...

text

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/svg-layered-spec.md (reported line 228)May include surrounding context.

箭头连线

svg
<!-- 垂直向下箭头 -->
<path d="M500,160 L500,195" stroke="#94a3b8" stroke-width="1.5" marker-end="url(#arrowhead)"/>
<text x="510" y="180" font-size="9" fill="#94a3b8" font-family="system-ui">标注文字</text>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes Kroki-based rendering but does not disclose that diagram source text may be transmitted to an external rendering service, which can expose internal architecture, credentials accidentally embedded in examples, or other sensitive design data. In a diagramming skill, users are likely to paste real system flows and infrastructure details, so the omission meaningfully increases the risk of unintentional data exfiltration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents capabilities that involve reading/writing local files, accessing environment variables, and making network requests to external services, but it does not declare any tool scope or permissions. This weakens least-privilege controls and can cause users or hosting agents to authorize broader actions than the metadata suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is written as a Chinese-only skill description and presents the skill as oriented toward Chinese output support, but nowhere in the file does it offer the user a language choice or state that the skill is intentionally limited to a Chinese-speaking context. Under the policy, language or locale constraints should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documentation instructs users to execute npx, which downloads and runs code from a package registry at invocation time. Even though it is framed as a fallback for rendering, it expands the skill from diagram generation into arbitrary third-party code execution on the local host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documented command npx -y @mermaid-js/mermaid-cli pulls and executes the latest package version at runtime without pinning, creating a supply-chain risk. If the upstream package or one of its dependencies is compromised, users could execute unreviewed code on their machine simply by following the skill instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction says that when generating or fixing SVG, Chinese text should be uniformly output in &#xXXXX; form, which presumes Chinese-language content rather than offering a user-selectable language or locale. This is a natural-language policy concern because the file title and guidance are entirely Chinese-focused with no opt-in or alternative for other languages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the full diagram source to a remote Kroki endpoint by default (https://kroki.io) without any explicit consent prompt, warning, or guardrail. In an agent skill context, users may provide internal architecture diagrams, hostnames, credentials accidentally embedded in diagrams, or other sensitive design data, which would be exfiltrated to a third-party service and could violate confidentiality or compliance requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The changelog text is written in Chinese and states the file records version changes, but provides no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for natural-language constraints, this can be interpreted as imposing a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The page markup declares English in the HTML tag, but the visible instructional text is only in Chinese: "将下面的内容替换为你的 Mermaid 代码,然后直接用浏览器打开本文件即可查看。" This imposes a specific language on users without opt-in or justification, matching the natural-language locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This SVG contains visible labels and title text in Chinese, such as the title and component names, but provides no natural-language indication that the language was user-selected or that the artifact is intentionally region-specific. That can violate a language/locale policy requiring user choice or explicit justification for a forced locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This SVG embeds all instructional labels and flow descriptions in Chinese, with only partial English glosses in some actor names. Because the file contains natural-language content and does not indicate that it is intentionally region-specific or offer an alternative locale, it appears to impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This SVG diagram uses Chinese labels throughout, including the title and component descriptions, but the file provides no natural-language indication that the skill is intended only for Chinese-speaking users or a China-specific context. Under the language/locale policy rule, forcing a specific language without opt-in or documented justification can be a policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This SVG includes user-visible labels in Chinese such as "网关" alongside English identifiers, and the file provides no natural-language context indicating that a specific language was intentionally chosen or that users can select a locale. Under the policy, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This SVG contains user-facing natural-language content entirely in Chinese, including labels such as '用户', '认证服务', and login-status messages, with no indication that language selection is optional. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This SVG is a natural-language artifact and its visible labels are predominantly Chinese throughout the diagram. Under the policy rule for all file types, forcing a specific language without user opt-in or documented regional justification is a locale-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.