T09 · Insecure Skill Coding Practices
- Location
scripts/ancientman_enhanced.py:467- Finding
Unbounded Text Compression Can Corrupt Code, Configuration, Queries, and Safety-Critical Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Chinese response-compression skill does not show data theft or persistence, but it needs review because its broad auto-activation and lossy rewriting can silently change code, configuration, search queries, and retrieved document text.
Install only if you intentionally want Chinese compressed/stylized responses and can tolerate lossy rewriting. Do not use it by default for security, legal, medical, operational runbooks, code/config editing, retrieval pipelines, or any workflow where exact wording matters unless compression is explicitly gated, reversible enough for your use case, and original text is preserved separately.
scripts/ancientman_enhanced.py:467Unbounded Text Compression Can Corrupt Code, Configuration, Queries, and Safety-Critical Instructions
The description promises a functional response mode that compresses Chinese outputs by about 75%, preserves technical accuracy, is optimized for several Chinese LLMs, and supports a classical literary compression style. The supplied code does not actually implement that core behavior. Its main implemented function is detecting whether user input contains trigger phrases for enabling or disabling the mode, selecting an intensity, and inferring a platform hint. The compression function is mostly a placeholder: only 'lite' mode removes a few stock phrases, while 'full', 'ultra', and 'classical' simply return the input unchanged. There is no substantive Chinese-specific compression engine, no demonstrated 75% reduction behavior, no technical-accuracy preservation mechanism, and no real per-model adaptation beyond static guide text. This is a material description/behavior mismatch rather than a mere implementation detail.
Imposing a Chinese-only response mode without explicit consent can override user expectations and degrade comprehension for multilingual or non-Chinese users. In security, operations, or compliance contexts, forced language/style transformation may cause misunderstanding of critical instructions, warnings, or output details.
The trigger conditions are broad enough that ordinary requests such as '简洁点' or general token-efficiency language may activate the skill without clear user intent. This can silently switch the assistant into compressed mode, increasing the risk that important caveats, safety warnings, or procedural detail are omitted in sensitive contexts.
同一文档前文将古风小生模式定义为“完全无典故”“绝不使用典故”(L037-L049),但本节又明确写出“典故引用:适当引用诗词、历史典故”(L082),并在示例中实际使用诸葛亮、庖丁、屈原、伯乐等典故(L095-L100)。这是文档内部对技能意图的直接冲突,会误导使用者对该模式实际输出风格的预期。
The file is entirely in Chinese and does not indicate the language choice, scope, or require user opt-in, which can prevent many users and reviewers from understanding the skill’s behavior, limitations, and risks. In a security review context this reduces transparency and informed consent, and can hide problematic functionality from operators who do not read Chinese, making misconfiguration or unsafe deployment more likely.
This code file contains natural-language documentation that is exclusively in Chinese, including the module docstring and later inline usage guidance. Under the stated policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a policy violation.
L030-L055 的类文档描述该处理器会自动对 LLM 输入/输出应用压缩,并暗示这是实际生效的集成行为。但实现中 L083-L088 只是构造并返回 compressed_prompts,未显示改写 prompts;同时 L076-L077 定义的 _input_messages 与 _output_messages 从未更新,使 L100-L111 的统计信息与文档意图不符。
This code compresses full document contents and stores both compressed and original text in returned node structures, which can affect user data handling and downstream behavior. Although there are internal comments/docstrings, there is no explicit user-facing warning that document text will be transformed and original content retained in memory/output structures.
The retrieve method silently compresses the user's query before passing it to the base retriever, then mutates retrieved node text in place by replacing original content with compressed text. This is a safety-relevant behavior change affecting user data and system outputs, but the code provides no confirmation, logging, or explicit warning beyond implementation comments.
The skill is presented as a default Chinese/compressed response mode without requiring the user's language preference or explicit opt-in. In agent contexts, this can degrade comprehension, accessibility, and the quality of warnings or operational instructions, especially if the user expected another language or a full-detail explanation for risky actions.
L053-L065 将古风小生模式定义为“完全/绝不使用任何典故”,这是该模式的核心约束之一。但 L226-L229 及 L243、L251、L259、L294、L303 又明确要求或示例性使用诸葛、庖丁、李白、韩信等典故,和前述规则直接冲突。此类文档内部冲突会导致技能实际遵循的意图不明确。
The trigger list includes broad everyday terms like '古风' and '文言', which can cause the skill to activate unintentionally during unrelated conversations. In a prompt-driven agent, accidental activation can override the expected response style, reduce clarity, and interfere with safety-critical guidance by switching into compressed or stylized output without explicit user consent.
The file instructs the model to use a specific Chinese/classical-Chinese response mode and presents it as a reusable communication pattern, but does not clearly require user opt-in before applying that style. This can override user preferences, reduce clarity for some users, and interfere with higher-priority task requirements such as precise, plain-language safety or compliance responses.
SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. The module docstring presents the skill description entirely in Chinese despite the file being named 'ancientman_enhanced.py', and there is no opt-in, fallback, or justification that the tool is intended only for Chinese-speaking users or a region-specific context.
The help text and interactive prompt strings shown to users are Chinese-only, which enforces a specific language for operation without opt-in. Under SQP-3, this is a natural-language policy issue unless the locale constraint is explicitly documented and justified or users are given a language choice.
The module docstring states the skill's core goal is to convert text into '极简文言' and presents this as the default behavior. This is a natural-language locale/style constraint that forces a specific language register without offering the user a choice, which matches the language/locale policy-violation criteria.
The file explicitly defines a forced Chinese classical compression mode as its core behavior, and nothing in the implementation provides a user opt-in, consent check, or easy fallback to normal style. In an agent setting, enforcing a stylistic/linguistic transformation can override user intent, degrade clarity, and alter safety-critical technical content, especially because the compressor aggressively deletes particles, punctuation, and courtesy phrases.
The module description states the skill operates in a classical Chinese style and emphasizes using highly compressed literary Chinese. This imposes a specific language/locale behavior by design, with no indication that users can opt in, opt out, or request another language.
The formatting logic strips phrases such as '请' and rewrites Chinese phrasing to a prescribed style, which enforces a specific language register. Because the file does not present this as a user-selectable option, it can violate language/locale policy expectations requiring choice or explicit opt-in.
The module description, comments, trigger vocabulary, and output behavior are primarily defined in Chinese, indicating the skill is designed around a specific language/locale by default. The file does not offer a language choice or explain why a Chinese-only mode is required, which conflicts with the policy against forcing a specific language without user opt-in.
The instructions say WorkBuddy should infer which Chinese model platform the user may come from and adjust response style accordingly. Inferring language or locale-linked style preferences from user phrasing, rather than asking or offering a choice, can conflict with policies requiring explicit user opt-in for such preferences.
The natural-language content in the module docstring is entirely in Chinese, including the title and all usage examples, which imposes a specific language/locale on users without any opt-in or alternative. Under the policy, language constraints should either offer user choice or be clearly justified as region-specific.
L053-L054 将参数成对描述为“压缩输入/解压缩输出”,而字段名 compress_output 与 L092-L098 的逻辑是当该开关开启时对生成文本执行 decompress。这使接口命名与文档意图不一致,调用者可能误以为开启后会压缩输出,实际却会解压。
The natural-language documentation strings in this file are exclusively Chinese, which may impose a language constraint on users without offering a language choice. Under the policy, forced language or locale without opt-in can be a natural-language policy violation unless clearly justified.
模块和类文档都表明这是“古代人模式检测器”,但测试函数实例化的是未定义的 CavemanModeDetector(),与前面实际定义的 AncientmanModeDetector 相矛盾。这不是单纯的信息缺失,而是注释/文档对应的演示入口与实际代码行为发生直接偏离,导致主程序无法执行预期测试。
No suspicious patterns detected.