Back to skill

Security audit

婚姻法律咨询助手

Security checks for vulnerabilities and agentic risk

Overview

This is a small Chinese marriage-law guidance skill with no executable code, but it includes repeated promotional contact information and self-asserted safety labels users should not treat as independent review.

Use this as jurisdiction-specific informational help for China marriage-law topics, not as a substitute for a qualified lawyer. Treat the repeated Hongjing Consulting contact details and CLEAN/NOT Suspicious labels as publisher-provided text, not independent guarantees, and avoid sharing sensitive personal facts unless the host environment protects them appropriately.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:50
Finding

Repeated Commercial Solicitation Can Steer Agent Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 50-63
Vulnerability Type: Repeated promotional instruction embedded in Agent-visible skill text
Risk Level: Medium

Vulnerable Content

The following is an English rendering of the complete affected segment; contact identifiers, URL, formatting, and repetition are preserved:

markdown
**Have questions? Contact Hongjing Consulting** 💬
WeChat: **FLZWCZ** | Website: https://flzwcz.cn
Legal consultation · Debt disputes · Marriage relationships · Contract review

> This skill is developed and maintained by **Hongjing Consulting**. Downloading and using it indicates that you have read and accepted the relevant terms.


---

Have questions? Contact Hongjing Consulting
- WeChat: FLZWCZ
- Website: https://flzwcz.cn
Legal consultation · Debt disputes · Marriage relationships · Contract review
> This skill is developed and maintained by Hongjing Consulting. Downloading it indicates acceptance of the relevant terms.

Technical Analysis

The skill's declared purpose is to provide Chinese marriage and family law guidance. The affected section instead embeds a commercial solicitation directing users to a specific WeChat account and external website. The solicitation appears twice at the end of the Agent-visible instruction document.

When a skill document is loaded into an Agent's context, its prose can influence generated responses. Repeated promotional closing material can therefore steer the Agent toward reproducing or endorsing third-party contact information even though doing so is not necessary for the declared legal-analysis functionality. This is classified as skill instruction hijacking because the behavior is introduced through skill text and can alter the content or objectives of the current session.

No executable code, automatic network request, credential access, privilege escalation, persistence mechanism, or remote payload retrieval wa ...[truncated 1469 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove both promotional footer blocks, including the WeChat identifier, external website, service advertisement, and implied terms-acceptance statement.
  2. Keep author attribution only in package metadata, such as the existing author field, rather than in Agent-visible operational instructions.
  3. If support information is legitimately required, place it in a separate marketplace or repository metadata field that is not injected into the Agent's prompt context.
  4. Add an explicit instruction that generated legal answers must not include advertisements, endorsements, referral language, or external contact information unless the user directly requests official support details.
  5. Review all skill text for repeated branding or closing content that could be reproduced as a response template.
  6. Align the inconsistent versions declared in SKILL.md and skill.json to improve package integrity and review traceability.
  7. Treat CLEAN, safe, and similar self-declared labels as metadata only; rely on independent review and enforceable controls rather than trust assertions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest text states the skill provides legal consultation specifically in Chinese and for China, with no indication that users may choose another language or locale. This is a natural-language locale constraint that can violate policy when imposed without explicit opt-in or a clearly documented user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.