Ae4
- Category
- analysis-evasion
- Confidence
- 80% confidence
- Finding
Suspicious Unicode normalization or mixed-script content
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a markdown-only news briefing skill that searches public robotics and embodied AI sources and keeps modification or posting actions behind explicit user approval.
Before installing, expect the skill to browse public robotics, AI, GitHub, and China ecosystem sources to prepare briefings. It should not use private accounts, tokens, authenticated content, or post externally unless you explicitly ask, and any proposed edits to its own reference files should be reviewed before approval.
Suspicious Unicode normalization or mixed-script content
The workflow explicitly directs the agent to scan QbitAI for China ecosystem news, and later requires a China Ecosystem category and China-specific checks. This imposes a locale/language-specific behavior as part of the default workflow rather than offering it as an optional user choice.
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
└── Priority scoring (source tier × recency × discussion volume)
Layer 3 — Output: ├── Template rendering (fill output_templates.md) ├── Distribution (email, Slack, Notion, blog) └── Archive (searchable database of past briefings)
The file’s user-facing guidance includes Chinese-specific trigger examples and bilingual phrasing, such as "GitHub 热门开源仓库" and mixed-language invocation examples, but does not state that the skill is China/Chinese-language specific or allow the user to choose language/locale. Under the policy, forcing or assuming a specific language without opt-in is a natural-language policy issue.
This markdown template is primarily written in English, but the section heading at L0196 switches to Chinese text without indicating that multilingual output is optional or user-selected. That can violate a language/locale policy requiring user choice rather than forcing a specific language fragment into generated output.
The brief template at L0300 introduces a Chinese heading inside an otherwise English format, but there is no surrounding instruction that this localization is opt-in. This can result in output that imposes a language choice on users unexpectedly.
The deep format uses Chinese text for a section title while the rest of the template is English, and no user language preference mechanism is described. This creates a locale inconsistency that may violate policy expectations around language choice.
The goal line specifies the section name as "⭐ GitHub 热门开源", which implicitly fixes part of the output in Chinese. Under the language/locale policy rule, this can be a concern when a file prescribes a specific language without offering the user a choice or documenting that the skill is intended for a Chinese-language context.
No suspicious patterns detected.