Back to skill

Security audit

Five Dynasties Ten Kingdoms Article 五代十国论文

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese history-writing skill with disclosed web research and reference-file use, and it does not show hidden execution, credential access, persistence, or destructive behavior.

Before installing, expect this skill to produce Simplified Chinese historical writing and to use web search or fetched public pages for citations and map links. Review cited facts and links before publication because the included draft/reference material contains some questionable dates, names, and wording quality issues.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description states the skill writes in Simplified Chinese when used, and later sections reinforce this as a fixed requirement. Because the policy category applies to all file types, this is a language/locale constraint that is imposed by default rather than offered as a user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's writing target lists '简体中文' as a mandatory characteristic of generated output. This forces a specific language/locale choice without indicating that the user may request another language or that consent is needed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill content is written in Chinese and does not indicate that language selection is optional or that the skill is intended only for a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'avoid' section tells the model not to use Traditional Chinese mixed writing, which further enforces a specific script policy. Without a user opt-in or documented justification for restricting script choice, this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire FAQ is written in Chinese and provides no indication that language selection is optional or that the skill is intentionally limited to Chinese-language users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file uses a single forced language throughout and does not indicate that Chinese is optional or required for a region-specific purpose. Under the policy rule for natural-language constraints, this can be a locale/language policy violation when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.