Back to skill

Security audit

BigFish · AI钓鱼助手(钓点分析·鱼情分析·钓点分享)| Spot Analysis · Fish Activity · Share Spots

Security checks for vulnerabilities and agentic risk

Overview

This fishing assistant is mostly coherent, but it needs review because it can accumulate location-linked fishing logs without clear privacy controls and includes guidance around bait it labels illegal.

Review this skill before installing if you do not want fishing photos, location, weather context, or catch history accumulated without explicit controls. Users should also verify local fishing regulations and avoid relying on any bait recommendation that may be illegal or restricted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Nearly all user-facing instructions, trigger phrases, and examples are presented only in Chinese, while the skill description contains only a brief English gloss. This effectively constrains use to a specific language without stating that the skill is Chinese-only or offering users a language/locale choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly describes handling photos, city or location information, weather-derived context, and persistent fishing logs, but it does not document consent, retention, sharing, or deletion practices. Because these data points can reveal travel patterns, frequented locations, and behavioral history, the absence of user-facing privacy controls creates a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include common conversational expressions such as '今天适合钓鱼吗' and '帮我分析鱼情', which can plausibly appear in ordinary chat and may cause unintended activation. Unintended activation can lead to unnecessary processing of user messages, images, or location-related context, increasing privacy exposure and confusing routing behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This YAML knowledge file is entirely written in Chinese and provides no indication that the skill is region-specific or that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The knowledge base explicitly includes an illegal bait option ('泥鳅') and labels it as prohibited, but still documents the fish targets and frames it as an effective method. In a fishing-assistant context, operational guidance about an illegal technique can normalize or enable unlawful behavior even if accompanied by a warning, making this a real policy and safety issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s title and all descriptive content are written entirely in Chinese, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill is expected to support broader users unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This YAML knowledge-base uses Chinese-only headings and fish descriptions, which can amount to a language/locale policy issue when a skill implicitly forces one language for users. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest-style YAML file presents all substantive guidance in Chinese and does not indicate that the user can select another language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.