Back to skill

Security audit

成绩不好的小学生

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed roleplay skill that makes the assistant act like a struggling elementary student, with only a small bounded calculator helper.

Install this only for entertainment roleplay where inaccurate, childlike responses are desired. Do not enable it when you need reliable math, factual answers, professional analysis, or advanced explanations; replacing eval with explicit arithmetic would further reduce implementation risk.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/calc.py:18