Back to skill

Security audit

Enforcement Assistant

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only legal procedure skill with expected sensitivity for court enforcement filings, but no hidden execution, data transmission, or persistence.

Install only if you need PRC civil enforcement filing guidance. Avoid entering unnecessary real ID numbers, addresses, account numbers, or third-party asset details into the agent, use only lawfully obtained and verified information, and confirm local court requirements or consult a qualified lawyer for strategy or sensitive investigations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are very broad and map to common legal-help questions, which can cause the skill to activate in contexts where the user may only want general discussion rather than procedural enforcement guidance. In a legal domain, unclear activation boundaries increase the chance of over-triggering, producing jurisdiction-specific procedural output without first confirming applicability, deadlines, or document type.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata and description scope it to post-judgment enforcement guidance, but the documented Scenario 4 expands into pre-judgment debt collection and lawsuit-filing assistance. This mismatch can cause the orchestration layer to invoke the skill in situations it was not designed or reviewed for, increasing the chance of inaccurate legal guidance and unsafe overreach beyond its declared boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are broad and overlap with generic legal-help requests such as '对方欠钱不还申请执行' or '帮我写执行申请书' without exclusion criteria. In a skill-routing context, this can cause overbroad activation, capturing unrelated or earlier-stage legal matters and presenting enforcement-oriented guidance where prerequisites like an effective judgment are missing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The templates explicitly solicit highly sensitive personal data such as ID card numbers, home addresses, and phone numbers, but provide no warning about minimization, redaction, secure storage, or lawful handling. In a legal-enforcement assistance context, users are likely to paste real data directly into the skill, increasing the risk of unnecessary collection, retention, disclosure, or misuse of personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The property-clue report template requests bank account numbers, property records, vehicle details, equity holdings, and receivables without cautioning users about legality, source reliability, or privacy constraints. Because this skill is designed for civil enforcement, it may encourage users to collect and submit highly sensitive third-party financial and asset data, creating substantial privacy, defamation, and misuse risks if the information is inaccurate, unlawfully obtained, or over-shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide instructs users to gather highly sensitive personal and financial information about a judgment debtor, including bank accounts, property, vehicles, social relationships, and pension-related assets, while providing only a brief generic statement about lawful evidence collection. Several suggested methods, such as asking neighbors, property management, intermediaries, or using commercial platforms, can easily lead users to over-collect personal data, misuse third-party disclosures, or violate privacy and data-protection rules if not tightly bounded by court-authorized or otherwise lawful procedures.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

All example user requests are presented only in Chinese, while the document does not state whether other languages are supported or offer users a language choice. Under the policy, forcing or implying a single language without opt-in can be a locale/language policy issue unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill says it provides procedural guidance only, but several sections recommend strategic actions such as settlement negotiations, hiring investigators, pursuing bankruptcy alternatives, or considering criminal prosecution. That inconsistency can mislead users and downstream systems about the level of legal decision-making the skill is performing, creating compliance and trust risks even if no direct code execution or data exfiltration occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The usage scenarios and sample requests are presented exclusively in Chinese, and the skill is framed around Chinese-language inputs without stating whether other languages are supported or allowing the user to choose. This can amount to a locale/language policy issue because the file effectively assumes a specific language rather than documenting it as an explicit, justified constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire document is written in Chinese and presents the guidance only in that language, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.