Back to skill

Security audit

ancient-man

Security checks for vulnerabilities and agentic risk

Overview

This Chinese response-compression skill does not show data theft or persistence, but it needs review because its broad auto-activation and lossy rewriting can silently change code, configuration, search queries, and retrieved document text.

Install only if you intentionally want Chinese compressed/stylized responses and can tolerate lossy rewriting. Do not use it by default for security, legal, medical, operational runbooks, code/config editing, retrieval pipelines, or any workflow where exact wording matters unless compression is explicitly gated, reversible enough for your use case, and original text is preserved separately.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ancientman_enhanced.py:467
Finding

Unbounded Text Compression Can Corrupt Code, Configuration, Queries, and Safety-Critical Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description promises a functional response mode that compresses Chinese outputs by about 75%, preserves technical accuracy, is optimized for several Chinese LLMs, and supports a classical literary compression style. The supplied code does not actually implement that core behavior. Its main implemented function is detecting whether user input contains trigger phrases for enabling or disabling the mode, selecting an intensity, and inferring a platform hint. The compression function is mostly a placeholder: only 'lite' mode removes a few stock phrases, while 'full', 'ultra', and 'classical' simply return the input unchanged. There is no substantive Chinese-specific compression engine, no demonstrated 75% reduction behavior, no technical-accuracy preservation mechanism, and no real per-model adaptation beyond static guide text. This is a material description/behavior mismatch rather than a mere implementation detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Imposing a Chinese-only response mode without explicit consent can override user expectations and degrade comprehension for multilingual or non-Chinese users. In security, operations, or compliance contexts, forced language/style transformation may cause misunderstanding of critical instructions, warnings, or output details.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are broad enough that ordinary requests such as '简洁点' or general token-efficiency language may activate the skill without clear user intent. This can silently switch the assistant into compressed mode, increasing the risk that important caveats, safety warnings, or procedural detail are omitted in sensitive contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

同一文档前文将古风小生模式定义为“完全无典故”“绝不使用典故”(L037-L049),但本节又明确写出“典故引用:适当引用诗词、历史典故”(L082),并在示例中实际使用诸葛亮、庖丁、屈原、伯乐等典故(L095-L100)。这是文档内部对技能意图的直接冲突,会误导使用者对该模式实际输出风格的预期。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely in Chinese and does not indicate the language choice, scope, or require user opt-in, which can prevent many users and reviewers from understanding the skill’s behavior, limitations, and risks. In a security review context this reduces transparency and informed consent, and can hide problematic functionality from operators who do not read Chinese, making misconfiguration or unsafe deployment more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation that is exclusively in Chinese, including the module docstring and later inline usage guidance. Under the stated policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L030-L055 的类文档描述该处理器会自动对 LLM 输入/输出应用压缩,并暗示这是实际生效的集成行为。但实现中 L083-L088 只是构造并返回 compressed_prompts,未显示改写 prompts;同时 L076-L077 定义的 _input_messages 与 _output_messages 从未更新,使 L100-L111 的统计信息与文档意图不符。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code compresses full document contents and stores both compressed and original text in returned node structures, which can affect user data handling and downstream behavior. Although there are internal comments/docstrings, there is no explicit user-facing warning that document text will be transformed and original content retained in memory/output structures.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The retrieve method silently compresses the user's query before passing it to the base retriever, then mutates retrieved node text in place by replacing original content with compressed text. This is a safety-relevant behavior change affecting user data and system outputs, but the code provides no confirmation, logging, or explicit warning beyond implementation comments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is presented as a default Chinese/compressed response mode without requiring the user's language preference or explicit opt-in. In agent contexts, this can degrade comprehension, accessibility, and the quality of warnings or operational instructions, especially if the user expected another language or a full-detail explanation for risky actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L053-L065 将古风小生模式定义为“完全/绝不使用任何典故”,这是该模式的核心约束之一。但 L226-L229 及 L243、L251、L259、L294、L303 又明确要求或示例性使用诸葛、庖丁、李白、韩信等典故,和前述规则直接冲突。此类文档内部冲突会导致技能实际遵循的意图不明确。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad everyday terms like '古风' and '文言', which can cause the skill to activate unintentionally during unrelated conversations. In a prompt-driven agent, accidental activation can override the expected response style, reduce clarity, and interfere with safety-critical guidance by switching into compressed or stylized output without explicit user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs the model to use a specific Chinese/classical-Chinese response mode and presents it as a reusable communication pattern, but does not clearly require user opt-in before applying that style. This can override user preferences, reduce clarity for some users, and interfere with higher-priority task requirements such as precise, plain-language safety or compliance responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. The module docstring presents the skill description entirely in Chinese despite the file being named 'ancientman_enhanced.py', and there is no opt-in, fallback, or justification that the tool is intended only for Chinese-speaking users or a region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help text and interactive prompt strings shown to users are Chinese-only, which enforces a specific language for operation without opt-in. Under SQP-3, this is a natural-language policy issue unless the locale constraint is explicitly documented and justified or users are given a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring states the skill's core goal is to convert text into '极简文言' and presents this as the default behavior. This is a natural-language locale/style constraint that forces a specific language register without offering the user a choice, which matches the language/locale policy-violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly defines a forced Chinese classical compression mode as its core behavior, and nothing in the implementation provides a user opt-in, consent check, or easy fallback to normal style. In an agent setting, enforcing a stylistic/linguistic transformation can override user intent, degrade clarity, and alter safety-critical technical content, especially because the compressor aggressively deletes particles, punctuation, and courtesy phrases.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description states the skill operates in a classical Chinese style and emphasizes using highly compressed literary Chinese. This imposes a specific language/locale behavior by design, with no indication that users can opt in, opt out, or request another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The formatting logic strips phrases such as '请' and rewrites Chinese phrasing to a prescribed style, which enforces a specific language register. Because the file does not present this as a user-selectable option, it can violate language/locale policy expectations requiring choice or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description, comments, trigger vocabulary, and output behavior are primarily defined in Chinese, indicating the skill is designed around a specific language/locale by default. The file does not offer a language choice or explain why a Chinese-only mode is required, which conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The instructions say WorkBuddy should infer which Chinese model platform the user may come from and adjust response style accordingly. Inferring language or locale-linked style preferences from user phrasing, rather than asking or offering a choice, can conflict with policies requiring explicit user opt-in for such preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language content in the module docstring is entirely in Chinese, including the title and all usage examples, which imposes a specific language/locale on users without any opt-in or alternative. Under the policy, language constraints should either offer user choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

L053-L054 将参数成对描述为“压缩输入/解压缩输出”,而字段名 compress_output 与 L092-L098 的逻辑是当该开关开启时对生成文本执行 decompress。这使接口命名与文档意图不一致,调用者可能误以为开启后会压缩输出,实际却会解压。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language documentation strings in this file are exclusively Chinese, which may impose a language constraint on users without offering a language choice. Under the policy, forced language or locale without opt-in can be a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

模块和类文档都表明这是“古代人模式检测器”,但测试函数实例化的是未定义的 CavemanModeDetector(),与前面实际定义的 AncientmanModeDetector 相矛盾。这不是单纯的信息缺失,而是注释/文档对应的演示入口与实际代码行为发生直接偏离,导致主程序无法执行预期测试。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.