Back to skill

Security audit

高考 (Gaokao)

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Gaokao study-tracking skill that stores sensitive study data locally, with privacy cautions but no evidence of malicious behavior.

Before installing, understand that this skill is designed to keep a long-term local study record, including scores, weak areas, schedule behavior, preferences, and stress or burnout signals. Use it only for users who consent to that storage, avoid unnecessary personal identifiers, and be especially careful with tutor or parent reports involving minors.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · feedback.md (reported line 13)May include surrounding context.

md
# Learning Log

## What Works
<!-- Methods, schedules, explanations that helped -->
- Pomodoro 25/5 better than long blocks
- Error analysis same day → higher retention
- Morning math, evening memorization

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly stores ongoing feedback, inferred preferences, weak areas, behavioral patterns, and prediction accuracy in a persistent local file, which creates a user profiling record. Although it notes the data is local and editable, it does not clearly emphasize the sensitivity of this educational and behavioral data, define retention limits, or require explicit user consent before inferring and storing patterns.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'Update Triggers' table uses generic events such as 'Weekly' and 'Weak area improved' without defining who determines the condition, when exactly it fires, or any exclusions. In a markdown skill description, this lacks trigger specificity and could overlap with many routine study interactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly tells the agent to 'Track everything in ~/gaokao/' for a student context, which encourages persistent local storage of detailed study metrics without any privacy warning, minimization guidance, or consent boundary. Because this data can include academic performance, stress indicators, and potentially identifying information about minors, the issue is a real privacy/security weakness even if the intent appears operational rather than malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Tutor mode promotes multi-student tracking, cross-student comparison, parent reporting, and per-student directories, but provides no safeguards around consent, confidentiality, or data segregation. In this context the risk is heightened because the skill is designed for education workflows that may involve minors, making unauthorized disclosure or overcollection of sensitive student performance data a realistic harm.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file includes Chinese-only example phrases and exam-material terms at L044-L045 and L052, while the rest of the skill is written in English. This creates an implicit locale/language requirement without opt-in or explanation, which matches the language/locale policy violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file centers the skill around China's national college entrance exam and includes Chinese-language terms such as 高考 and 古诗词. While the regional purpose is apparent, the document does not explicitly state that this locale scope is intentional or offer any language/locale opt-in, which can create ambiguity under language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs persistent storage of detailed study data under ~/gaokao/, including profile, exam targets, province, scores, session logs, and feedback, without any notice, consent flow, retention limit, or privacy guidance. This can expose sensitive educational and personal data to other local users, backups, or unintended long-term retention, especially on shared devices.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file consistently uses Chinese labels and China-specific educational terminology throughout, but does not indicate that the language/locale is optional or user-selectable. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains extensive Chinese-language and gaokao-specific instructions, including Chinese subject labels, memorization targets, and example file content. Because the guidance is presented as the default study method without an explicit opt-in or justification that the skill is region-specific, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file consistently uses Chinese-language labels and a gaokao-specific context, but does not indicate that this locale and language are optional or user-selected. This can be a natural-language policy issue when a skill implicitly forces one language or locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.