Back to skill

Security audit

中文商务邮件写作助手

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Mandarin business email writing aid with no executable code, external access, persistence, or hidden behavior.

Install this skill if you want help drafting or polishing Mandarin business emails. It is not a general multilingual email-writing skill, so users needing other languages should use a different skill or explicitly ask the agent not to apply this one.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description and title state that the skill is for Chinese business emails and Mandarin professional context, which imposes a specific language/locale. The file does not indicate any user choice, opt-in flow, or justification as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and all templates are written exclusively in Chinese, indicating the skill is intended to operate in a fixed language. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file contains user-facing guidance only in Chinese, which can be interpreted as forcing a specific language without user opt-in. The policy allows locale constraints when clearly documented and justified, but this file provides no such justification or alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no natural-language indication that the language is optional, configurable, or intended only for a Chinese-speaking audience. Under the policy rule for language/locale constraints, forcing a specific language without user opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.