Back to skill

Security audit

Hutian Opc Culture Dd

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent due-diligence checklist skill with no executable behavior, but it should only be used with authorized and careful handling of sensitive company data.

Install only for authorized diligence work. Before using it operationally, define the diligence mandate, get written permission for company records and any brand/customer outreach, redact unrelated personal or banking details, use secure transfer and storage, and limit access to people with a need to know.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs users to collect backend screenshots, creator interviews, and other potentially sensitive business information, but it provides no privacy, confidentiality, or authorization safeguards. In a due-diligence context, this can lead users or downstream agents to request, store, or process non-public company data without clear need-to-know limits, consent boundaries, or secure handling expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends direct confirmation with brands and cross-checking bank statements and financial flows, which are highly sensitive activities involving confidential commercial and banking information. Without explicit controls on authorization, disclosure scope, redaction, and secure handling, this workflow could expose trade secrets, banking details, or confidential counterparties and create legal/compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The data-source inventory includes enterprise-provided financial data, contracts, audit materials, and platform statements, but the skill does not consolidate any warning about confidential handling or least-privilege access. Because this is a structured checklist, users may treat all listed materials as routine inputs and over-collect sensitive documents without appropriate safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction says all due-diligence reports must strictly follow the provided structure, which includes fixed English section titles such as 'Executive Summary'. This imposes a language/locale choice in the output format without any user opt-in or explanation that the skill is intentionally bilingual or region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document explicitly promotes user profiling, sentiment monitoring, competitor monitoring, intelligent customer service, and automated decision support, but provides no safeguards around lawful basis, consent, data minimization, retention, or human review. In a commercial due-diligence context, this can normalize privacy-invasive practices and lead operators to deploy monitoring and profiling systems in ways that violate privacy obligations or create compliance and reputational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file presents all instructions, labels, and templates exclusively in Chinese, and nowhere indicates that the user can choose another language or that the framework is intentionally limited to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written exclusively in Chinese and does not indicate that users may choose another language or locale. Under the policy rule for natural-language violations, a fixed language requirement without opt-in or documented justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs collection of highly sensitive financial materials such as full financial ledgers, platform statements, bank records, contracts, invoices, and receivables details, but it does not warn about confidentiality, data minimization, authorization, or secure handling. In a due-diligence workflow, this omission can lead users to over-collect or mishandle regulated or confidential business data, increasing privacy, contractual, and insider-information exposure risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The brand confirmation template directs users to contact third parties to verify contract terms, payments, and renewal intent without requiring prior authorization, confidentiality checks, or communication protocols. That creates a real risk of unauthorized disclosure of deal activity, commercial terms, or the existence of a transaction, which is especially sensitive in M&A and diligence contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The comprehensive checklist requests broad categories of highly sensitive records, including bank statements, tax filings, payroll/social security records, related-party transactions, guarantees, contingent liabilities, and litigation materials, with no safeguards for privacy, legal privilege, or secure handling. In aggregate, this creates a substantial risk of unnecessary collection and exposure of confidential corporate and personal data if the skill is followed operationally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The file is written entirely in Chinese and specifically recommends Chinese-language optimization and domestic tools such as 文心一言、文心一格、通义万相, but it does not state that the framework is China-specific or offer language/locale alternatives. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This file presents all guidance exclusively in Chinese and does not provide an opt-in, alternative language, or justification that the content is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The entire skill document is written only in Chinese and does not indicate that users may choose another language or locale. Under the policy rule for language/locale, this can be treated as a locale constraint that is not explicitly documented as optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file is entirely written in Chinese and presents compliance guidance, checklists, and templates only in that language, with no indication that other languages or locales are supported. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy concern, especially for a generic reference document not explicitly limited to a China-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

该 Markdown 文档从标题到全部说明均固定为中文表述,未见任何允许用户选择语言、或声明该文档仅适用于特定中文语境/区域的说明。根据规则,若技能内容强制特定语言且无用户选择或明确合理限定,属于自然语言层面的语言/区域策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.