Back to skill

Security audit

裁判者办案指引

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language legal workflow guide for judges and arbitrators, with no hidden execution, data access, persistence, or installation behavior found.

Before installing, treat this as jurisdiction-specific legal methodology guidance rather than binding legal authority. Users should verify cited practices against current law, court rules, and professional obligations, especially because adjudication and arbitration decisions are high-impact contexts.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill content, headings, trigger phrases, and example prompts are entirely in Chinese and present the workflow as the required interaction mode, with no indication that users may choose another language. This creates a natural-language policy concern because the skill effectively mandates a locale without explicit opt-in or documented justification.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
SQP-3 applies to all file types and covers language or locale policy violations. This skill content is presented exclusively in Chinese for its operational guidance, with no indication that users may choose another language or that the locale restriction is explicitly documented as an opt-in constraint within the file.

Static analysis

No suspicious patterns detected.