Back to skill

Security audit

Popeye Translation

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese-English translation helper with no code execution, data access, installation steps, or persistence.

Before installing, be aware that generic Chinese words like translation, polishing, and localization may activate the skill in ordinary translation requests; otherwise it appears limited to text assistance and does not add execution or data-access authority.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger words listed in the skill metadata are very broad, common natural-language terms that can easily appear in ordinary user requests. This can cause the skill to activate unintentionally, increasing the chance of prompt/context hijacking, unexpected behavior, or routing sensitive content into the skill without explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The quick-start section instructs users to invoke the skill with generic terms and examples, but it does not define when the system should or should not treat those words as activation commands. In environments where skills are selected from conversational text, this ambiguity can lead to accidental activation and make downstream prompt-injection or misrouting risks easier to exploit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase "帮我做本地化" is broad enough that ordinary conversation could activate this skill unintentionally when a user is merely asking for help with localization. In an agent environment with multiple skills, this increases the chance of incorrect routing, unexpected prompt injection surface exposure, or execution of this skill when another workflow was intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is written entirely in Chinese and defines Chinese trigger phrases and a Chinese response template, which effectively imposes a specific language/locale for using the skill. Although the prompt allows the target translation language to be Chinese or English, the invocation and surrounding interaction format do not offer the user an explicit language choice for operating the skill itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The title and prompt template constrain the interaction to Chinese-English translation (中英互译, 中译英/英译中) rather than offering language choice. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase 帮我翻译 is very generic and likely to match ordinary user requests outside a deliberate skill invocation flow. That can cause accidental activation or routing conflicts, leading the system to apply this skill when the user did not explicitly intend it, which is a genuine security and reliability concern in agentic environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Natural-language policy review applies to all file types. The title, trigger phrases, and interaction example all assume Chinese-language use, but the file does not state that the skill is intentionally limited to Chinese users or offer language/locale opt-in, which may conflict with organizational language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.