Back to skill

Security audit

数学教育助手

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 math tutoring skill made of Markdown guidance and references, with no executable code or hidden privileged behavior found.

Install this if you want a Simplified Chinese K12 math assistant. Review the broad activation examples if your environment has many skills, because it may be invoked for loosely worded math-help requests, but the artifacts do not show unsafe access or hidden behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata says it should trigger for broad math-learning requests in natural language, without meaningful boundaries on when it should defer or require explicit invocation. This can cause overbroad activation, leading the skill to intercept unrelated or ambiguous conversations and potentially expose internal references, mishandle user intent, or override safer/default behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description is written as a requirement that the skill operate as a Chinese math education assistant, but it does not state that Chinese is optional or user-selectable. A fixed language expectation without opt-in can violate language/locale policy for skills intended for broader audiences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples include very common phrases like 'what is', 'help me explain', and 'I got it wrong' with no exclusions, which increases the chance of accidental activation on ordinary conversation. In a host system with multiple skills, this can produce unintended routing, privacy issues from unnecessary processing of user content, or denial of correct handling by a more appropriate skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all grading rules, templates, and feedback text only in Chinese, and does not indicate that the skill is intended exclusively for Chinese-speaking users or provide any user opt-in for language selection. Under the policy for natural-language violations, forcing a specific language without user choice is in scope.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The metadata specifies the skill language as "中文(简体)", and the rest of the listing presents the skill as Chinese-only without offering opt-in language selection. Under the policy, forcing a specific language without user choice or a clearly documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The listing says users can interact using natural language without fixed commands, but it does not clearly constrain activation to math-learning requests. In a multi-skill environment, broad invocation language can cause unintended routing or activation on loosely related prompts, increasing the chance the skill handles requests outside its intended scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage section explicitly states that no commands are needed and that natural-language speech is sufficient, but it lacks guardrails on when the skill should not trigger. This ambiguity can lead to overbroad matching, accidental invocation, and inappropriate handling of requests beyond the declared educational scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document title and description are entirely in Chinese and present the resource as a general-purpose knowledge reference for skill explanation, quiz generation, and Q&A. There is no indication that Chinese is optional, user-selected, or required for a region-specific purpose, which can conflict with a language/locale choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and it does not mention that the language is optional or limited to a specific locale or audience. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.