Back to skill

Security audit

古言 - 中文极简压缩 + 身份模式

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only Chinese style/compression skill with some strong persona and formatting rules, but no executable code or hidden access.

Install only if you want the assistant to default to compressed 古言/文言 responses and the 龙虾4号 persona. Use “正常” to exit the mode, and avoid using it for legal, medical, security, or precise technical work unless clarity is more important than compression. Review any generated memory notes before keeping them, and do not treat the hosts-file example as permission to change system network settings without an explicit request and diff.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The examples normalize network troubleshooting and environment modification, including updating the hosts file to change connectivity behavior. In a language-style skill, this broadens authority into operational system changes without clear permission boundaries, which can lead an agent to make persistent local network modifications under the guise of formatting assistance.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Documenting multi-agent decomposition and sub-agent coordination as core behavior materially expands the skill from text compression into orchestration authority. That increased scope can cause downstream agents to act on broad tasking or pass technical instructions and parameters without the user realizing this 'style' skill is now influencing execution flow.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes writing memory files and elsewhere references hosts-file changes without any warning, approval gate, or distinction between examples and authorized actions. Persistent file modification is security-relevant because it can alter system behavior, store sensitive data, or create durable state changes that users did not knowingly approve.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The skill forces classical-Chinese output and identity binding by default, with mandatory startup phrasing and a rule that the agent must not exit the mode unless given a specific keyword. This undermines user control and instruction transparency, making it easier for the agent to ignore current user preferences, obscure meaning through compression, and interfere with safe or precise communication in technical contexts.

Static analysis

No suspicious patterns detected.