Back to skill

Security audit

胡田 OPC导师 AI资产知识产权保护

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only IP guidance skill is not malware, but it gives high-impact legal filing guidance that could lead users to sign inaccurate AI-use declarations and mishandle sensitive identity documents.

Treat this as a rough checklist, not legal advice. Before installing or using it for filings, verify current requirements with official authorities or qualified IP counsel, do not sign any statement that is not true for your materials, do not pad or fabricate code, and tightly control or redact identity documents, source code, business records, and dataset samples before submission.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The handbook tells applicants to declare that submitted materials were '未使用AI生成', despite the skill being about protecting AI成果. This can induce users to submit false statements to a government-facing process, creating legal, compliance, and fraud risk; in this skill context, the contradiction makes the issue more dangerous because users are likely to rely on the guidance as authoritative.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The commitment-letter template explicitly instructs the user to sign a statement that the materials were not automatically generated by AI. If the work or documents were AI-assisted, this guidance encourages a signed false declaration, which could expose users to rejection, penalties, or broader legal liability; because the skill markets legal protection for AI成果, users may be especially likely to follow it without questioning its legality.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The manual instructs users to upload身份证 and real-name-verification materials but gives no privacy, minimization, storage, or transmission safeguards. In a document intended to operationalize filings, omission of handling controls can lead to unnecessary exposure of highly sensitive personal data, especially if users mirror the checklist into shared folders, email, or third-party workflows.

Static analysis

No suspicious patterns detected.