Back to skill

Security audit

Mental Models Cn

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese mental-model reference skill with some documentation inconsistencies and broad triggers, but no hidden execution, credential access, persistence, or exfiltration behavior was found.

Install this as a Chinese-language educational reference skill. Expect broad analysis-related triggers and verify advice independently, especially for investment or business decisions, because the package contains outdated/inconsistent model counts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code is clearly related to the declared theme of mental models and analysis frameworks, so this is not an unrelated or malicious skill. However, the description materially overstates and somewhat mischaracterizes the implementation. The declared purpose says there are 108 models in 16 series with a cycle analysis practical guide, while the code comments and data define a recommendation engine with 73 models and a smaller set of series. The code does include cycle-analysis-related scenario handling, but it does not itself provide a distinct '实战指南' beyond generated recommendations and a generic analysis framework. Therefore the description does not accurately represent the actual implemented scope and primary behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese and presents all headings, descriptions, and guidance in a single language without any opt-in or alternative locale indication. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue when no justification or opt-in is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The changelog documents broad trigger additions such as '/mental-model', '推荐模型', '行业分析', '投资决策', and '竞争策略' without any visible activation constraints, narrowing rules, or exclusions. In an agent skill system, overly generic triggers can cause unintended invocation during normal conversation, leading to prompt hijacking of user intent, inappropriate skill activation, or increased exposure to downstream risky behaviors in the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The newly added trigger phrases include ambiguous everyday-language terms that are likely to appear in ordinary user requests. Because this is a mental-models analysis skill, these phrases fit broad analytical conversations, which makes accidental activation more likely and increases the chance that the skill overrides or distracts from the user's actual task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title explicitly identifies the skill as 'mental-models-cn', and the entire document is written only in Chinese with no indication that users can select another language or opt in to a locale-specific experience. Under the policy, a language constraint should either offer user choice or be clearly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire installation guide is written in Chinese, and there is no indication that the skill is region-specific or that alternative languages are available. This creates a natural-language locale policy issue because it effectively requires Chinese comprehension without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely written in Chinese and presents the skill content as the default operating language, but it does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the natural-language policy rules, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description states '108 个思维模型,16 个系列,含周期分析实战指南', which implies a substantially larger and more structured content set. In this README, the skill documents only 25 models and 5 visible categories, with update history confirming completion at 25 models, so the described scope does not match the actual documented contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all user-facing instructions and navigation in a single language, which can constitute a language/locale policy violation when no user opt-in or justification is provided. The file does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is explicitly labeled "mental-models-cn" and all listed triggers are Chinese phrases, which indicates a language-specific interaction model. The file does not offer users a language choice or state that Chinese is optional, creating a potential language/locale policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The triggers "如何分析" and "用什么模型" are generic phrases that can appear in many ordinary conversations, not just requests intended for this skill. Because the manifest does not provide scope constraints or negative examples, these broad phrases could cause unintended activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all instructions, labels, and usage guidance in Chinese and does not indicate that users can choose another language. The policy requires flagging language or locale constraints when a specific language is effectively forced without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents its title and all user-facing content in Chinese only, which effectively imposes a specific language on users. The policy allows locale constraints only when they are clearly documented and justified or when users are given a choice, neither of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains user-facing instructions solely in Chinese, including the title, workflow steps, examples, and FAQ, but does not provide any opt-in, alternative language, or justification for the language restriction. Under the policy rule for language/locale, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · UPDATE-GUIDE.md (reported line 94)May include surrounding context.

md
vim skills/mental-models/MODEL-CARDS.md

# 4. 更新 SKILL.md 版本号
vim skills/mental-models/SKILL.md

# 5. 发布
clawhub publish skills/mental-models/ --version 1.1.0 --slug mental-models-cn

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · UPDATE-GUIDE.md (reported line 107)May include surrounding context.

md
vim skills/mental-models/MODEL-CARDS.md

# 4. 更新 SKILL.md 版本号
vim skills/mental-models/SKILL.md

# 5. 发布
clawhub publish skills/mental-models/ --version 1.1.0 --slug mental-models-cn

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · UPDATE-GUIDE.md (reported line 120)May include surrounding context.

md
vim skills/mental-models/MODEL-CARDS.md

# 4. 更新 SKILL.md 版本号
vim skills/mental-models/SKILL.md

# 5. 发布
clawhub publish skills/mental-models/ --version 1.1.0 --slug mental-models-cn

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · UPDATE-GUIDE.md (reported line 133)May include surrounding context.

md
vim skills/mental-models/MODEL-CARDS.md

# 4. 更新 SKILL.md 版本号
vim skills/mental-models/SKILL.md

# 5. 发布
clawhub publish skills/mental-models/ --version 1.1.0 --slug mental-models-cn

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all instructional content in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate a language/locale policy where skills should not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing instructional content in Chinese and does not indicate that users can opt into another language. Under the policy, forcing a specific language without user choice or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file uses Chinese throughout for headings, instructions, examples, and warnings, but does not indicate that the skill is Chinese-only by design or provide any user opt-in for language/locale. Under the policy rule, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown skill file presents all instructional content in a single language and locale context, with no opt-in, alternative language guidance, or statement that the skill is intended only for Chinese-speaking users. The policy specifically calls for flagging language or locale constraints when a skill effectively forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing instructional content in Chinese and does not indicate that users can choose another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file appears to force a specific language/locale for all users through its title, headings, and body text. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructional content in Chinese and does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.