Back to skill

Security audit

teaching-plan-writer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese lesson-plan writing template with disclosed web-search behavior and no executable code, persistence, credential use, or hidden data access.

Install this if you want a Chinese-curriculum lesson-plan assistant and are comfortable with it using web search for lesson topics. Avoid entering private student data, and verify any generated curriculum citations or downloadable document links before relying on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger logic activates on effectively any user input or keyword, which makes the skill overly eager and increases the chance it will intercept unrelated conversations. Overbroad activation is dangerous because it can cause unintended tool use, unnecessary web access, leakage of unrelated user content into the skill workflow, and poor containment of the skill to its intended domain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description contains broad trigger conditions like helping whenever a user needs to write lesson plans, teaching designs, or teaching plans, which can match many ordinary education-related requests. Overly broad activation increases the chance the skill is invoked when the user did not explicitly ask for it, causing prompt hijacking of the interaction scope and unintended instruction precedence over the base assistant behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is written entirely in Chinese and implicitly enforces Chinese-language behavior without stating whether other user languages are supported or how language preference should be handled. This can override user language choice, reduce transparency, and create unsafe or misleading behavior if the assistant responds in an unexpected language or misinterprets requests due to locale assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, with no indication that other languages are supported or that the user can choose a preferred language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file is written as a role requirement entirely in Chinese and frames the assistant as operating within Chinese curriculum standards, but it does not state that language choice is optional or user-selected. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern unless the restriction is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The role requirements expand the skill beyond lesson-plan drafting into broad web searching and collection of at least 20 online lesson plans, creating a capability mismatch with the declared skill scope. Scope drift is dangerous because it can trigger unnecessary external data access, increase prompt-injection exposure from untrusted web content, and cause the agent to perform actions users did not clearly authorize.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Requiring the skill to output a downloadable Word-format link introduces an undeclared output/action capability beyond simple lesson-plan generation. This is risky because link generation can enable phishing, unsafe file delivery, or exfiltration workflows if the storage location or link target is not tightly controlled and disclosed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is entirely presented in Chinese and is explicitly scoped to Chinese language instruction, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all instructional content only in Chinese and does not offer an alternative language, translation note, or user opt-in, which can be interpreted as forcing a specific language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, which can be a language policy concern if the organization requires user opt-in before forcing a specific language. There is no note explaining that the skill is region-specific or offering an alternative language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructions and activity descriptions exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in or documented regional justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill content is presented only in Chinese, and there is no indication that users may choose another language or that the skill is intended solely for a Chinese-language audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.