Back to skill

Security audit

胡田 OPC导师 发布前自查向导

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only release checklist is mostly coherent, but it pressures audited skills to add reciprocal promotional links that could affect later user-facing outputs.

Before installing, treat this as a commercial release checklist, not a neutral security-only review tool. Use it only if you want promotional and pricing review, and require explicit approval before adding referral hooks or links to any Skill output or instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:244
Finding

Mandatory Cross-Promotion Hijacks Audited Skill Outputs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the document content are written entirely in Chinese, and the skill appears targeted to all users under a broad skill system rather than a clearly documented China-only or Chinese-only compliance context. Under the stated policy, forcing a specific language without opt-in or explicit justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage note states that every Skill must complete this template before release, and the entire template is written as a Chinese-language document with no indication that another language is permitted. This creates a natural-language policy concern because it effectively imposes a specific language/locale requirement without offering user or team opt-in or alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

该文件是自然语言模板文档,适用SQP-3检查。L308写明“每个Skill发布前必须执行”,而文档整体仅提供中文指引,未说明这是面向特定中文团队或地区的限定场景,也未给出用户语言选择,存在默认强制使用单一语言/locale流程的政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "每个Skill发布前必须完成评分" appears in a Chinese-only reference document and presents the process as mandatory without any indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all user-facing instructions in a single language and does not indicate that users may choose another language. Under the natural-language policy rule, forcing a specific language without user opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file applies to all users of the release process via '每个Skill发布前必须执行', but the document is written only in Chinese and does not indicate any language choice or locale limitation. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.