T01 · Skill Instruction Hijacking
- Location
standards/post-process-elements-standard-v1.md:16- Finding
Mandatory Organization-Specific Branding Hijacks Generated Deck Outputs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly supports deck production, but its global rules can impose a specific academy logo and insurance-event footer on generated presentations.
Review and edit the branding standards before installing or using this skill for client or non-Zhumeng decks. Confirm any logo, footer, QR code, upload destination, and token/link retention explicitly, and avoid running the PPTX inspection script on confidential decks unless local JSON/stdout output is acceptable.
standards/post-process-elements-standard-v1.md:16Mandatory Organization-Specific Branding Hijacks Generated Deck Outputs
This finding shows a second description-behavior mismatch: instead of only orchestrating a production pipeline, the skill reportedly inspects/parses existing PPTX files, extracts slide text and media counts, and emits JSON-style analysis. In a deck-production context, that is more dangerous because presentations often contain confidential business content, speaker notes, customer data, and proprietary visuals, so undisclosed parsing and reporting can expose sensitive information or enable unreviewed data handling.
This finding shows a second description-behavior mismatch: instead of only orchestrating a production pipeline, the skill reportedly inspects/parses existing PPTX files, extracts slide text and media counts, and emits JSON-style analysis. In a deck-production context, that is more dangerous because presentations often contain confidential business content, speaker notes, customer data, and proprietary visuals, so undisclosed parsing and reporting can expose sensitive information or enable unreviewed data handling.
The skill description is written entirely in Chinese and presents the skill as a general-purpose PPT production workflow, but it does not state that Chinese output is optional or limited to a China-specific/regulatory context. This can indicate a locale policy issue because the skill appears to impose a specific language without user opt-in.
The skill appears to have file-writing capability without declaring any explicit tool scope or permissions, which breaks least-privilege expectations and makes it harder to review what the skill can actually do. In a production workflow that handles PPTX assets, delivery packages, and uploads, undeclared write access increases the risk of unintended file modification, data corruption, or misuse of local resources.
This markdown file uses Chinese throughout, including the title and checklist items, which can amount to forcing a specific language for users without any opt-in or explanation. Under the policy rule, language-specific content should either offer user choice or clearly justify the locale constraint.
The document title and all checklist content are written exclusively in Chinese, which indicates a fixed language choice in the skill artifact. There is no visible note that the skill is China-specific or that users may opt into another language, which can violate a language/locale choice policy.
This markdown file is entirely written as a fixed Chinese presentation outline, with repeated instructions for specific on-slide wording and no indication that another language may be used based on audience preference. Under the policy rule for natural-language violations, a skill that imposes a single language without opt-in can be a locale-policy issue.
The entire skill file is written only in Chinese and provides no indication that users may choose another language or that the locale restriction is intentionally limited to a China-specific audience. Under the policy rules, forcing a specific language without opt-in is a natural-language policy violation.
The script requires specific Chinese directory names and filename keywords such as '成品PPT' and '内容大纲', which effectively enforces a single language/locale. This is a natural-language policy concern because users with differently localized package structures are not given any opt-in, alternative locale handling, or documented justification in the file.
The entire standard is written as a Chinese-only instruction set and provides no indication that users may choose another language or locale. Under the policy rule for natural-language violations, forcing a single language without opt-in can be a locale-policy issue.
The file title and the entire instructional content are written exclusively in Chinese, with no indication that language selection is optional or that the skill is region-specific. Per the policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.
This markdown file contains operational guidance only in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The entire standard is written only in Chinese and gives mandatory formatting/content rules without offering any language or locale choice. Under the policy, forcing a specific language without explicit user opt-in is a natural-language policy violation unless clearly documented as a justified locale-specific skill, which is not stated here.
The file is written entirely as a normative standard in Chinese and explicitly specifies Chinese text limits and Chinese font requirements, such as '微软雅黑 / Microsoft YaHei'. This can constitute a language/locale policy violation because it effectively forces a specific language/locale without any user opt-in or stated region-specific justification.
The file’s instructions and requirements are fully specified in Chinese, which effectively forces a specific language for users or operators consuming this skill. Under the policy, language constraints should either be optional/opt-in or clearly justified as region-specific; neither is stated here.
This markdown template is entirely written in Chinese, including headings and report fields, which implies a fixed output language. Under the policy rules, forcing a specific language without user opt-in or documented regional justification is a natural-language policy violation.
The entire skill template is written as a Chinese-only instruction set and provides no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.
This markdown file presents all user-facing instructions in a single language and does not offer any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified.
The subagent execution prompt is entirely in Chinese and provides no language selection, fallback, or opt-in despite being an operational workflow prompt. In a multilingual environment, this can cause operators or downstream agents to misunderstand gating requirements, delivery criteria, or safety constraints, leading to incorrect execution or bypass of required review steps.
The workflow explicitly instructs uploading a deliverable and then recording file tokens, links, and node identifiers, but provides no guardrails around destination trust, access control, data sensitivity, or user consent. In a production deck pipeline, outputs may contain proprietary client materials, branding assets, or internal content, so normalizing upload and link retention without disclosure controls can lead to unintended data exposure or persistence in external systems.
The title and the entire protocol are written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
The checklist states a default preference tied to '野哥偏好' and then says reviews and suggestions should default to a high-density standard. Because the document is written entirely in Chinese and frames this default as a preset user confirmation, it can be interpreted as enforcing a preset preference rather than offering a user choice. This is a natural-language policy concern if the skill is expected to adapt to user language/locale preferences unless explicitly opted in.
This markdown file contains natural-language instructions and descriptions only in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy concern.
This code reads textual content from presentation slides and prints it to stdout, optionally persisting it to disk as JSON. While the write is part of the script's purpose, there is no inline comment, docstring, or user-facing disclosure warning that the output may contain sensitive document contents.
The skill file is written as a standard titled entirely in Chinese and does not indicate that language is optional or user-selectable. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation when no locale justification is provided.
No suspicious patterns detected.