Back to skill

Security audit

Cultural Intelligence Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a low-risk cultural-awareness helper with no hidden data access, networking, persistence, or destructive behavior, though its executable handler is much simpler than its description suggests.

Safe to install from a security perspective. Expect lightweight, mostly templated output from the handler rather than a full cultural-intelligence coaching system, and note that some documentation/examples are in Chinese despite the manifest declaring English.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a mismatch because the code's primary purpose does not materially implement the claimed functionality. It does not provide substantive cultural intelligence training, cross-cultural communication coaching, or global mindset development; instead it counts words, detects a few generic keywords like goals/challenges/urgency, and emits templated recommendations such as 'Build cultural intelligence for diverse environments.' There is no hidden resource access or undeclared external behavior, but the main behavior is far more generic and superficial than the declared purpose, so the description overstates what the skill actually does.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The README mixes some English examples with predominantly Chinese descriptive and instructional content, which effectively imposes a language preference on users. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The markdown includes an entire usage scenario and expected output in Chinese, but the skill does not explain that multilingual output is optional or user-selected. This can create an implicit language/locale preference in the skill description without an explicit opt-in, which falls under the language/locale policy concerns for natural-language content.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The manifest sets "language": "en", which imposes a specific language choice. Under the policy, language constraints should either be user-selectable or explicitly justified as region-specific; no such opt-in or justification appears in this file.

Static analysis

No suspicious patterns detected.