Back to skill

Security audit

法律文书生成器

Security checks for vulnerabilities and agentic risk

Overview

This is a local legal-document template skill, but it overstates compliance/review status and lacks clear safeguards for high-stakes legal use.

Review before installing. This skill appears non-executable and local, but users should treat its output as draft templates only, confirm the applicable jurisdiction and facts, and get qualified legal review before signing, filing, or relying on any generated document.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill generates legal documents that users may rely on for divorce, debt, labor, property, and litigation matters, yet it does not warn that outputs may be incomplete, jurisdiction-specific, or unsuitable without professional review. In this context, omission of a legal-risk disclaimer can materially mislead users into treating generated text as legally sufficient, which may cause loss of rights, invalid filings, or harmful contractual commitments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger set includes very generic phrases such as “法律文书”, “合同模板”, and common legal task requests, which can cause the skill to activate in situations where the user did not explicitly intend to invoke it. In a legal-assistance context, unintended activation is risky because it may steer users toward template-based legal outputs in sensitive matters without clear consent or context validation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions, examples, and descriptions are presented only in Chinese, with no indication that users may select another language or locale. SQP-3 covers natural-language locale policy violations when a skill enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The metadata is entirely Chinese-language and targets Chinese legal-document scenarios without any indication of locale selection or user opt-in, which effectively biases activation and output toward a specific language/legal context. In legal workflows, this can create confusion or misuse if a user expects another jurisdiction or language, potentially producing unsuitable templates for their actual needs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.