Back to skill

Security audit

Embodied Ai News

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only news briefing skill that searches public robotics and embodied AI sources and keeps modification or posting actions behind explicit user approval.

Before installing, expect the skill to browse public robotics, AI, GitHub, and China ecosystem sources to prepare briefings. It should not use private accounts, tokens, authenticated content, or post externally unless you explicitly ask, and any proposed edits to its own reference files should be reviewed before approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow explicitly directs the agent to scan QbitAI for China ecosystem news, and later requires a China Ecosystem category and China-specific checks. This imposes a locale/language-specific behavior as part of the default workflow rather than offering it as an optional user choice.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
80% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · references/workflow.md (reported line 435)May include surrounding context.

└── Priority scoring (source tier × recency × discussion volume)

Layer 3 — Output: ├── Template rendering (fill output_templates.md) ├── Distribution (email, Slack, Notion, blog) └── Archive (searchable database of past briefings)

text

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s user-facing guidance includes Chinese-specific trigger examples and bilingual phrasing, such as "GitHub 热门开源仓库" and mixed-language invocation examples, but does not state that the skill is China/Chinese-language specific or allow the user to choose language/locale. Under the policy, forcing or assuming a specific language without opt-in is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown template is primarily written in English, but the section heading at L0196 switches to Chinese text without indicating that multilingual output is optional or user-selected. That can violate a language/locale policy requiring user choice rather than forcing a specific language fragment into generated output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The brief template at L0300 introduces a Chinese heading inside an otherwise English format, but there is no surrounding instruction that this localization is opt-in. This can result in output that imposes a language choice on users unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The deep format uses Chinese text for a section title while the rest of the template is English, and no user language preference mechanism is described. This creates a locale inconsistency that may violate policy expectations around language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The goal line specifies the section name as "⭐ GitHub 热门开源", which implicitly fixes part of the output in Chinese. Under the language/locale policy rule, this can be a concern when a file prescribes a specific language without offering the user a choice or documenting that the skill is intended for a Chinese-language context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.