Back to skill

Security audit

曾仕强

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable persona skill, but it needs Review because its advice content can present broad cultural stereotypes and traditional family or gender roles as default guidance.

Install only if you specifically want a Zeng Shiqiang-style, Chinese cultural-philosophical persona. Treat its management, relationship, and parenting output as perspective-taking rather than neutral or evidence-based advice, and be careful applying it to multicultural workplaces, HR decisions, family conflict, gender roles, or vulnerable users.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (21)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The module frames a single culturally specific management philosophy as a general decision model ('总纲') and repeatedly presents contrasts such as '西方/中国' in a way that can steer users toward one normative worldview without prompting for context, alternatives, or limitations. In a persona skill this is not code-execution dangerous, but it can still produce biased, overgeneralized, or inappropriate advice when applied to multicultural, legal, HR, or organizational settings.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The text explicitly generalizes interpersonal guidance as applying to '中国人', which can steer the agent toward culture-wide essentializing without user consent or contextual qualification. In a persona skill, this is risky because the model may reproduce stereotype-like advice, over-apply culture-specific assumptions, and give exclusionary or biased responses to users who do not identify with that framing.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The module repeats and reinforces a sweeping nationality-based stereotype that 'Chinese people are the most prone to anger.' Even though it is presented as a distilled quotation and interpretive commentary, it attributes a negative emotional trait to a protected national group in broad terms, which can normalize biased reasoning and produce discriminatory or stigmatizing outputs when the skill is invoked.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
This section explicitly frames modern problems and normative judgments through a single Chinese cultural-philosophical lens and presents that lens as broadly applicable guidance, without an explicit opt-in, balancing perspective, or limitation language at the point of use. In a persona skill, that can bias outputs toward one worldview, especially on social, ethical, or cross-cultural questions, and may marginalize users who did not request that framing.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The module content is entirely written in Chinese and defines a Chinese-language persona/voice without any indication that the user’s preferred language should be detected or respected. This can override user expectations and cause unintended disclosure, exclusion, or degraded usability when the surrounding system or user expects another language.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The module strongly prescribes a single moral-philosophical framework (e.g., ‘凭良心’, ‘儒家为根本’, and deterministic responsibility framing) as normative guidance, without an explicit requirement to first confirm the user wants that lens. In a persona skill this can steer users toward worldview-laden advice as if it were generally applicable, which is risky for sensitive interpersonal, family, or management decisions.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The module frames culturally specific claims about 'Chinese people' as broadly normative and behaviorally prescriptive, which can steer the agent to essentialize users based on ethnicity or cultural background. In a persona skill, this is risky because the model may apply stereotypes without user opt-in, reducing fairness and producing biased or exclusionary advice.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The text endorses a single communication style ('顺性而为', indirectness, face-preserving tactics) as the effective or correct default, without context limits or alternatives. This can cause the agent to privilege one cultural norm in situations where directness, transparency, consent, or anti-manipulation safeguards are more appropriate, leading to harmful guidance in workplace or interpersonal settings.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The cited section makes broad, generalized claims about 'Chinese people' versus 'Western people' as if these are fixed, essential traits, which can reinforce stereotypes and present culture-linked behavior as innate truth. In a persona skill, this is especially risky because the model may reproduce these claims as authoritative guidance across unrelated user contexts, leading to biased or exclusionary outputs.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The module presents culturally loaded family-structure guidance, including claims about marriage stability, single-parent households, and parent-child outcomes, as generally applicable advice without a clear safety or context warning. In a persona skill meant to be invoked for real-life parenting and family questions, users may interpret normative and potentially stigmatizing statements as endorsed guidance, which can reinforce harmful decisions or emotional harm to vulnerable users.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The content endorses fixed gender and family roles, such as assigning total breadwinning responsibility to fathers and prescribing rigid parental role patterns, without offering user choice, modern context, or alternatives. Because this skill is designed for advice-like use in management, relationships, and family education, such statements can be surfaced as authoritative recommendations and may promote discriminatory or coercive dynamics in real households.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The module consistently presents one Chinese cultural and family-value framework as the default lens for parenting, marriage, gender roles, filial duty, and family structure without clear opt-in, cultural scoping, or balancing caveats. In a general-purpose agent skill, this can lead to normative advice that is misapplied to users from different cultures or vulnerable users, reinforcing bias, exclusion, or harmful family pressure under the appearance of authoritative guidance.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The module defines broad applicability across many user phrasings and domains such as leadership, interpersonal issues, emotion handling, and classical philosophy, without precise trigger boundaries. In an agent setting, this can cause the skill to activate for loosely related prompts and override more appropriate specialist skills, leading to misleading guidance, policy bypass through persona framing, or unsafe responses in adjacent domains the skill says it does not cover.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The module presents a broad essentialist claim that 'Chinese people' are inherently more emotionally volatile and uses that stereotype as the basis for advice. In a persona skill that may be invoked as authoritative guidance, this can normalize discriminatory generalizations, bias outputs across many user interactions, and cause the model to treat nationality as a behavioral trait without evidence or user opt-in.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
This quoted passage explicitly ranks Chinese people as more emotionally volatile than people from all other countries, which is a culture-based stereotype stated as fact. Even when attributed to source material, including it uncritically in a callable skill increases the chance the agent will reproduce harmful generalizations in responses and justify biased treatment or exclusionary advice.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The text claims Chinese people value self-cultivation more than all other nationalities, which is another sweeping culture-wide assertion. While less directly harmful than the volatility claim, it still encodes essentialist beliefs about nationality and can bias downstream responses toward overgeneralized cultural judgments.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The cited lines prescribe marital and gender-role norms as general guidance ('夫妇开始', male/female role framing) without clear user consent, contextual limitation, or neutrality safeguards. In a persona skill framed as wisdom/advice, this can steer users toward normative relationship beliefs that may be inappropriate, exclusionary, or harmful in sensitive family situations.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The file repeatedly instructs the persona to speak from a single culturally bounded frame ('我们中国人……') as a default rhetorical pattern, without any user opt-in or adaptation guidance. This can lead to cultural essentialization, exclusion of users outside that identity, and potentially biased or inappropriate responses when the skill is invoked in broader contexts.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The tone summary codifies a culturally specific speaking style as the persona's baseline behavior, including value-laden defaults such as privileging '情理' and presenting a singular national style. In practice, this can cause the agent to over-apply cultural assumptions in unrelated user contexts, reducing safety, inclusivity, and appropriateness of responses.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file hard-codes a Chinese-language, Chinese-cultural interpretive framework and presents it as the default reasoning path for many user questions, without indicating language fallback, locale adaptation, or user-consent checks. This can cause mismatched responses for users from other linguistic or cultural contexts, reducing reliability and potentially introducing biased or inapplicable guidance in sensitive interpersonal or decision-making scenarios.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file is entirely structured around Chinese-language persona behavior and repeatedly assumes Chinese-only framing without providing a mechanism to detect or respect the user's preferred language. In an agent skill, this can degrade usability, mis-handle user intent, and create prompt-routing bias, especially for multilingual users who did not request Chinese output.

Static analysis

No suspicious patterns detected.