Back to skill

Security audit

中小团队HR自动化工具包

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese HR document-template skill with legal and privacy caveats, but I found no hidden execution, persistence, exfiltration, or deceptive behavior.

Install only if you need Chinese domestic HR document templates. Treat every generated contract, termination notice, handbook, and compliance answer as a draft for HR or legal review, and handle completed employee forms as sensitive personal information with restricted access, retention limits, and secure storage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill repeatedly presents itself as compliant with Chinese labor law and suitable for generating HR/legal documents, but it does not clearly constrain use to PRC employment scenarios or verify jurisdiction before giving compliance-oriented outputs. This can mislead users in other regions into relying on inapplicable legal templates or advice, creating legal, privacy, and employment-compliance risk.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description broadly advertises 'HR automation' and 'one-click generate' for multiple document types, but it does not specify what exact user requests should invoke this skill or where its scope ends. In a manifest file, this kind of broad capability wording can overlap with many ordinary HR-related requests and may cause unintended invocation.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The template title and the entire handbook content are written in Chinese, with no indication that language selection is optional or that the template is intended only for a Chinese-speaking or China-specific context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The form collects a broad set of personally identifiable and sensitive employee data, including ID number, contact details, home address, and emergency contact information, but provides no privacy notice, purpose limitation, retention guidance, access restriction, or consent language. In an HR context this data collection may be operationally relevant, but omitting handling and privacy safeguards increases the risk of over-collection, misuse, unauthorized disclosure, and noncompliance with applicable personal information protection requirements.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The entire template is written in Chinese and provides no indication that language selection is optional or that the skill is intentionally limited to Chinese-language/legal contexts. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The entire template is written in Chinese, including the title, greeting, body, and field labels, with no indication that language selection is optional or that the template is intended only for a Chinese-speaking or region-specific context. This creates a natural-language policy concern because it imposes a specific language/locale by default rather than offering user opt-in or documenting a justified constraint.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This template is a legal employment-termination document, but it provides no warning that employers must verify the stated grounds, compensation, procedure, and local legal requirements before use. In an HR automation skill aimed at non-specialists, users may rely on the form as legally sufficient, creating a meaningful risk of unlawful termination, labor disputes, or regulatory noncompliance if the placeholders are completed incorrectly or without counsel review.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
The name, description, and tags are all presented in Chinese, which can imply a fixed language experience without stating whether users may choose another language. Because policy violations include forcing a specific language without user opt-in, the metadata should document that the skill is Chinese-only for a justified domestic context or offer language choice.

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
The file presents all instructions and fields exclusively in Chinese and does not offer any language selection, alternative locale, or indication that the form is intended only for a specific language audience. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This markdown skill file presents the contract exclusively in Chinese and does not indicate that users can choose another language or locale. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is reportable unless the locale constraint is explicitly documented and justified.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown template forces a specific language/locale for all users and does not provide any indication that Chinese is optional or limited to a China-specific context. Under the stated policy, a skill should not impose a language without user opt-in unless the locale constraint is clearly documented and justified.

Static analysis

No suspicious patterns detected.