Back to skill

Security audit

Daily Idiom

Security checks for vulnerabilities and agentic risk

Overview

This skill teaches Chinese idioms and includes disclosed, opt-in scheduled notifications with local preference storage.

Install this if you want a Chinese idiom learning skill. Only enable push notifications for user IDs and external channels you control, and use the documented off command if you no longer want scheduled messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is narrowly educational, yet the skill also exposes push-notification management, per-user preference storage, external channel selection, and CLI administration commands. That mismatch is dangerous because it conceals a larger operational surface that could be used to collect user identifiers, send unsolicited messages, or administer external messaging actions beyond what a user would reasonably expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is narrowly educational, yet the skill also exposes push-notification management, per-user preference storage, external channel selection, and CLI administration commands. That mismatch is dangerous because it conceals a larger operational surface that could be used to collect user identifiers, send unsolicited messages, or administer external messaging actions beyond what a user would reasonably expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title, tagline, and usage guidance are presented in Chinese and target Chinese-language idiom study, but the file does not explicitly state that output language is user-selectable or that Chinese responses occur only with user opt-in. This can create a language-policy issue for users who trigger the skill via English keywords such as "idiom" or "learn Chinese".

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad and loosely defined, so ordinary conversation about idioms, Chinese learning, or related games could invoke the skill unintentionally. Unintended invocation becomes more dangerous here because the skill appears to have stateful and notification-related capabilities, meaning accidental activation could lead to unexpected data handling or workflow changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documentation for a learning skill includes user push-management commands for multiple external platforms, indicating capabilities beyond simple content delivery. In context, this is risky because a benign-looking educational package can function as a notification distribution mechanism, which may enable spam, unauthorized outreach, or privacy-impacting user tracking if not tightly governed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Cross-platform push-channel management is broader than what is necessary to teach a daily idiom and introduces unnecessary external-integration risk. The additional channels enlarge the attack and misuse surface by enabling message delivery to third-party services, potentially exposing user identifiers or supporting unsolicited communications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script defines weekday names in Chinese and emits a fully Chinese prompt string, which forces a specific language/locale for users. Under the policy criteria, this is a natural-language locale violation because there is no opt-in, fallback, or documented justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script emits a fixed prompt requiring Chinese idioms, Chinese examples, and Chinese mnemonic content, with no option for the user to choose another language or locale. This is a natural-language policy issue because it imposes a specific language unconditionally rather than offering opt-in or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code selects among Telegram, Feishu, Slack, and Discord and emits cron-control commands to create scheduled outbound messages. For a skill described only as teaching one idiom per day, this orchestration capability is not clearly justified unless push delivery and channel integration are declared as part of the skill’s intended scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill for presenting a daily Chinese idiom with origin, meaning, examples, and memory tips. This script implements operational features for enabling scheduled pushes across channels and persisting per-user delivery settings, which are materially broader behaviors than the content-focused description suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits status and confirmation messages in Chinese in multiple user-facing console outputs, but there is no indication that the skill is China-specific or that users can choose their preferred language. That creates a natural-language policy concern because the skill imposes a locale/language choice without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The README presents the skill as delivering one Chinese idiom every day and targeting Mandarin/Chinese learning, which imposes a language-specific experience. Because the file does not explicitly frame this as an opt-in language choice or a clearly justified locale-restricted tool, it may conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file documents automatic morning and evening pushes and shows commands to enable delivery to external channels like Telegram, Feishu, Slack, and Discord. The description does not include any warning that enabling the feature will send scheduled messages to those platforms or mention channel/privacy implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The package description states the skill provides a 'Daily Chinese idiom (成语)' and focuses on building Chinese vocabulary, which implies a fixed language/locale experience. Under the policy rule, language-specific behavior should either offer user choice or clearly document a justified locale constraint; this manifest text does not do so.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.