Back to skill

Security audit

Mao Colleague

Security checks for vulnerabilities and agentic risk

Overview

The skill does not show clear malicious behavior, but it needs Review because a methodology assistant requests broad local file and shell authority while bundling maintenance scripts that can modify or delete files and under-disclosed logging/progress behavior.

Install only after reviewing the broad local permissions. Prefer a project-scoped or sandboxed install, avoid the global install unless you trust the publisher, pin or review dependencies before pip install, and do not let the agent run internal maintenance scripts without checking their target paths. Avoid entering sensitive personal, political, legal, or private business content unless you accept possible Mao-framed analysis and the logging/progress-tracking ambiguity.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (34)

exec() call detected

High
Category
Dangerous Code Execution
Content
all_success = True
    for module_name, class_name in modules_to_test:
        try:
            exec(f"from {module_name} import {class_name}")
            print(f"  ✅ {module_name}.{class_name}")
        except Exception as e:
            print(f"  ❌ {module_name}.{class_name}: {e}")
Confidence
95% confidence
Finding
The use of exec() to dynamically construct and execute an import statement is dangerous because it turns data into code. In this file the current module/class list is hard-coded, which reduces immediate exploitability, but the pattern is still a true vulnerability: if an attacker can influence module_name/class_name, the working directory, sys.path, or imported module resolution, they may trigger unexpected code execution during validation.

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill grants powerful capabilities via `allowed-tools: Read, Write, Edit, Bash`, and the installation instructions also invoke `git clone` and `pip install`, which imply network and shell activity. If the permission model relies on explicit declarations beyond prose/tool metadata, this mismatch can cause users or policy engines to underestimate what the skill can actually do, enabling broad filesystem modification and command execution.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The documented purpose is a methodology assistant, but the analyzed behavior includes bulk corpus processing, test modification, report generation, filename repair, and other maintenance/prototype tasks unrelated to the advertised user-facing function. This is dangerous because a user invoking a seemingly informational assistant may unknowingly trigger extensive local file reads/writes and maintenance workflows across project directories.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The logging middleware records full raw_input and user_id and may write them to disk or stdout without minimization, redaction, or consent controls. Because this assistant processes free-form user questions, logs can easily capture sensitive personal, business, or credential-like content and expose it through log access, aggregation systems, or support workflows.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The script performs filesystem mutations that include deleting an existing destination file before renaming another file into place. That is a real destructive capability, and it is not aligned with the declared purpose of an AI analysis assistant, which increases the risk of unexpected data loss if this utility is invoked in the skill environment.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
This code rewrites filenames in the processed data store based on JSON content and summary metadata, and deletes any existing conflicting target file first. Because filenames are derived from mutable data, a malformed or duplicated title can cause unintended overwrites and loss of processed artifacts.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README explicitly tells users to trust the system's recommendations because of claimed '78%+' accuracy, but it does not provide balancing warnings about model fallibility, bias, domain limits, or the need for human verification. This can lead users to over-rely on the skill's outputs for strategic or consequential decisions, especially since the skill markets itself as an intelligent analysis and decision-support system.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The skill explicitly instructs outputs to use Mao Zedong-specific terminology and conceptual framing, which constrains assistant style without user opt-in. While not directly enabling code execution or data exfiltration, it can override user preference, bias responses toward ideological framing, and reduce neutrality or appropriateness in unrelated contexts.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation states that the system automatically tracks user learning progress, history, time, and recommendations, but it does not disclose what data is stored, where it is stored, how long it is retained, or whether users can opt out. In a skill context, undisclosed persistence of behavioral data can expose sensitive usage patterns and create privacy and compliance risks if the data is later accessed, shared, or mishandled.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The documentation presents the skill as operating in Chinese and centered on a specific persona/style without clearly offering a user language or tone choice. This can override user preference, reduce accessibility, and increase the risk of unwanted ideological or stylistic steering in downstream interactions, especially in multilingual or enterprise contexts.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The output guidance explicitly prescribes Mao-style phrasing, terminology, and rhetorical patterns without opt-in, which can pressure the model toward a fixed ideological voice regardless of user context. In practice this may produce manipulative, inappropriate, or noncompliant responses for users expecting neutral, professional, or localized communication.

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The router enables request logging middleware during initialization without any visible disclosure, consent, or privacy control, while later code logs raw_input and user_id. In a conversational assistant, users may reasonably submit sensitive text, so undisclosed capture increases privacy and compliance risk even if no external attacker is involved.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Deleting an existing destination file without confirmation is a direct data-loss risk. If the mapping is wrong, stale, or collides with a legitimate file, the original file is removed irreversibly before the rename completes.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The processed-file path has the same unsafe overwrite pattern: it deletes an existing JSON target before renaming the current file. In a data store driven by titles and metadata, collisions are plausible, so this can silently destroy valid records.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The script unconditionally deletes an existing destination file before renaming the source file into place. If the size-based match is wrong, the destination already contains valid data, or the rename fails after deletion, this can cause irreversible data loss and makes the operation unsafe for a local file-management utility.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The feedback form explicitly requests email and Discord/Telegram contact details, but it provides no privacy notice, purpose limitation, retention policy, access controls, or handling instructions. This creates a real privacy and compliance risk because testers may disclose personally identifiable information without informed consent, and the collected data could be mishandled, over-retained, or exposed.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The test plan explicitly calls for observation, questionnaires, interviews, usage logging, and optional screen recording, but only briefly mentions a generic consent form without defining data minimization, retention, access controls, or a clear privacy notice. This can lead to collection of personally identifiable or sensitive behavioral data without adequately informed consent or sufficient safeguards, creating privacy and compliance risk during user testing.

Natural-Language Policy Violations

High
Confidence
96% confidence
Finding
The file contains explicit praise and justification of killing, coercion, and terror against identified groups, presented in affirmative language and later reinforced by summary sections that frame such violence as methodologically valuable. Even though this is historical source material, in an agent skill knowledge base the text can be surfaced without guardrails, enabling the model to echo or normalize violent political action.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The document endorses widespread arming and mobilization of peasants, including language encouraging universal weapon possession and dismissing fear of such weapons. In a skill context, this can prime the model to legitimize armed organization or provide supportive framing for violent collective action, especially because the surrounding metadata highlights the text's 'methodological value.'

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The prompt explicitly instructs the system to generate content that reads as if Mao Zedong is speaking, creating a historical-persona impersonation behavior without user opt-in, disclosure, or safer framing such as analysis/simulation. In a conversational agent, this can mislead users into treating outputs as authentic or endorsed representations of a real historical figure, especially given the strong emphasis on realism and behavioral consistency.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The prompt is written entirely in Chinese and instructs generation of Chinese-language content without offering any user language choice or opt-in. This can exclude users, cause misunderstanding of outputs, and create safety/compliance issues if users cannot properly review or challenge generated guidance. In context, this appears to be a localization/design issue rather than an attempt to deceive, but the all-encompassing language framing across the whole file makes the problem persistent.

Ssd 2

Low
Confidence
88% confidence
Finding
The trailing embedded token sequence '<|end▁of▁thinking|>' appears to be a model-control or prompt-boundary style artifact inserted into otherwise normal prose. In an agent skill context, special-token strings can act as prompt injection primitives, confuse downstream parsers, or unintentionally alter model behavior if this document is later ingested as instructions or context.

Ssd 3

Medium
Confidence
96% confidence
Finding
The code logs user-provided input in plaintext, which creates a direct data exposure surface for anything users type, including secrets, personal data, internal business information, or regulated content. This is more dangerous in assistant software because prompts are unstructured and commonly contain sensitive context that operators did not explicitly request for storage.

Ssd 4

Medium
Confidence
84% confidence
Finding
The extreme-scenario templates encourage 'no conditions, create conditions and proceed,' 'self-reliance,' and mass mobilization in resource-starved contexts, while the simulator is optimized to force such rhetoric for tests. In a guidance-generating skill, this can systematically bias outputs toward reckless escalation and action without adequate safety, legal, or operational constraints, increasing the chance of harmful real-world advice in crisis or deprivation scenarios.

Session Persistence

Medium
Category
Rogue Agent
Content
### Claude Code
```bash
# 项目级安装
mkdir -p .claude/skills
git clone https://github.com/wwwaapplleecu-source/mao-skill .claude/skills/mao-colleague

# 或全局安装
Confidence
90% confidence
Finding
The installation instructions place the skill in `.claude/skills` or `~/.claude/skills`, including a global location that persists across sessions and projects. Persistent installation increases blast radius because a skill with Read/Write/Edit/Bash access may remain available unintentionally, affecting future sessions or unrelated repositories without fresh review.

Static analysis

No suspicious patterns detected.