Back to skill

Security audit

博辩

Security checks for vulnerabilities and agentic risk

Overview

This skill is a text-analysis and short-comment generator for Chinese posts, with no code execution, data access, persistence, or hidden external behavior found.

Before installing, understand that this is a specialized Chinese-text workflow. It may activate on broad requests like article analysis or support/opposition comments, so users should invoke it when they specifically want AI-style writing analysis or short grounded comments for Chinese posts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples include very broad phrases such as ‘分析这篇文章’ and ‘帮我从正反两面评论’, which overlap with common user intents unrelated to this narrow skill. In an agentic system, this can cause unintended invocation, routing ordinary analysis/commentary requests into a specialized workflow that performs extra classification and persuasion-oriented output the user did not explicitly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description states that the skill analyzes 普通中文博文, and later examples and supported content are all constrained to Chinese text. This is a language/locale restriction presented as a fixed requirement, but the file does not explicitly frame it as an opt-in user choice or justify the constraint as a region-specific requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.