Back to skill

Security audit

孙子兵法决策视角

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only Chinese Sunzi strategy-advice skill with some stylized presentation quirks but no code execution, credential use, persistence, or hidden data flow.

Install this if you want a Chinese Sunzi-style strategic framing for competitive decisions, negotiations, or post-mortems. Be aware it may activate on broad strategy wording, uses a forceful first-person style, and is not designed for ordinary relationship, parenting, or collaborative advice despite including boundary warnings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases include broad everyday language such as questions about how to fight, whether to confront directly, or how to think about something strategically. Overbroad activation can cause the skill to engage unexpectedly in unrelated contexts, potentially overriding safer default behavior or steering benign conversations into adversarial framing.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill claims to be a non-roleplay perspective, yet it instructs the agent to speak in first person as the framework and to minimize repeated disclosure. That mismatch can obscure to users that they are interacting with a stylized mode, increasing the risk of deceptive presentation and making it harder for users to recognize when answers are shaped by preset rhetoric rather than normal assistant behavior.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation says this is not roleplay, but the operational rules direct embodiment in a first-person voice with constrained disclosure and a special exit condition. This inconsistency can mislead users and downstream systems about the mode's nature, creating transparency and consent issues even if the content is not overtly harmful.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill requires a specific language and rhetorical style, including first-person framing, highly assertive phrasing, and specialized expressions, without requiring explicit user opt-in. Forced style constraints can suppress normal safety/clarity behaviors, reduce accessibility, and make outputs sound unjustifiably certain in sensitive strategic or conflict-related discussions.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This file is a markdown document, so natural-language policy checks apply. The content consistently uses Chinese only, and there is no indication that the skill is intentionally region-specific or that users can opt into another language, which can violate a language/locale policy requiring user choice.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file presents all instructions and guidance in Chinese only, and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file content is entirely in Chinese and presents operational guidance without indicating that language choice should follow the user's preference. This can override or constrain the assistant's response language unexpectedly, reducing usability and potentially causing misunderstandings in strategic advice contexts.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
This markdown file presents all user-facing instructional content in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. The policy requires flagging language or locale constraints when a specific language is effectively forced without user choice or justification.

Static analysis

No suspicious patterns detected.