Back to skill

Security audit

编写企业客户培训大纲并生成DOCX文档

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese enterprise-training outline generator that creates a DOCX, with only minor usability and file-location cautions.

Installers should expect this skill to draft Chinese business-training outlines and save a DOCX. Before using it with sensitive client or internal training information, confirm the output path and avoid overwriting existing documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

整个技能说明仅以中文定义名称、描述和输出要求,默认引导代理以中文完成交互与内容生成,但未说明可根据用户偏好切换语言。若组织要求尊重用户语言选择,这种隐含的单一语言约束可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keywords include broad everyday phrases such as '写大纲' and '课程大纲', which can cause the skill to activate in contexts the user did not intend. Mis-triggering a skill that generates structured business documents and then proceeds to create output files can lead to unintended actions, confusion, or disclosure of user-provided business information into an unnecessary artifact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill instructs the agent to generate a DOCX and write it to a user-specified path or default working directory, but it does not require an explicit safety check, path confirmation, overwrite warning, or notice about where data will be stored. In context, the content may contain internal corporate training plans or customer details, so silent file creation can create privacy, integrity, or accidental overwrite risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire template is written as a prescriptive course-outline structure in Chinese, with formatting and tone requirements that implicitly force output in Chinese. There is no indication that users may choose another language, nor any documented regional or compliance reason for this locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.