Back to skill

Security audit

语义压缩

Security checks for vulnerabilities and agentic risk

Overview

This is a small Chinese-language semantic-compression prompt wrapper with no hidden network, credential, persistence, or privilege behavior, but it does not compress text locally and can expose the full input to a downstream LLM.

Install only if you are comfortable with a Chinese-language prompt-based helper. Treat the CLI/API output as a prompt that still contains the original input, not as already-compressed or privacy-minimized text. Review model-produced compressed results before using them as memory or replacing originals, and avoid including secrets or unrelated sensitive context in the same LLM request.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/compress.js:37
Finding

Indirect prompt injection through untrusted text concatenation

Content
View full analysis

Vulnerability Details

File Location: scripts/compress.js, lines 37-49
Vulnerability Type: Indirect prompt injection caused by insecure prompt construction
Risk Level: Medium

javascript
function semanticCompress(text, options = {}) {
  const defaultOptions = {
    targetCompression: 0.5,
    preserveAccuracy: true,
    model: null
  };
  const config = { ...defaultOptions, ...options };
  
  const fullPrompt = COMPRESSION_PROMPT + '\n' + text;
  return {
    prompt: fullPrompt,
    originalLength: text.length,
    originalTokens: Math.ceil(text.length / 4),
    config: config
  };
}

Technical Analysis

The text argument is appended directly to the LLM instructions without a structured trust boundary, escaping mechanism, or explicit rule that directives contained in the source text must be treated only as data. The README documents that consumers can submit the resulting result.prompt to an LLM.

If text contains attacker-controlled instructions, the receiving model may interpret those instructions as part of the active prompt rather than as content to compress. An attacker could consequently redirect the model away from compression, manipulate its output, or request disclosure of information present elsewhere in the model context.

This is an insecure prompt-construction pattern rather than evidence of intentional instruction hijacking by the Skill itself.

Attack Path

  1. An attacker places adversarial instructions in a document, conversation history, or other text processed by the Skill.
  2. A caller passes that content to semanticCompress.
  3. Line 43 concatenates the untrusted content directly after the compression instructions.
  4. Following the documented workflow, the caller submits result.prompt to an LLM.
  5. The model may follow the embedded attacker instructions instead of treating them solely as source material.
  6. The generated output may contain a ...[truncated 718 chars]
Remediation
View remediation

Remediation Suggestions

  1. Send trusted compression instructions and untrusted source content as separate structured messages or API fields rather than combining them into one prompt string.
  2. State explicitly in the trusted instruction layer that the source text is untrusted data and that any instructions, role declarations, tool requests, or formatting commands inside it must not be followed.
  3. Enclose the source text in an unambiguous data structure, such as a JSON field, while clarifying that delimiters do not independently provide a security boundary.
  4. Apply input-size limits and reject unsupported input types before constructing the request.
  5. Validate the model response against the expected compression task. Reject outputs that contain tool calls, unexpected role changes, requests for secrets, or content unrelated to the supplied source.
  6. When sensitive context is involved, submit only the minimum data required for compression and avoid placing credentials, system instructions, or unrelated private material in the same model context.
  7. Add adversarial tests containing embedded instructions, fake role markers, delimiter-breaking attempts, and requests to reveal context.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims to perform semantic compression, but the documented behavior also implies file I/O and prompt-template generation rather than a narrowly scoped in-memory transformation. This mismatch is dangerous because users or orchestrators may grant broader trust or permissions based on the declared purpose, leading to unexpected local file access and unclear data-handling behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The inline documentation makes strong preservation and compression claims that the implementation does not satisfy. This mismatch is dangerous because security-sensitive systems may trust the documented behavior when handling long or sensitive context, leading to incorrect assumptions about minimization, retention, and token usage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises semantic compression but never compresses the input; it only wraps the original text in a prompt template and outputs that prompt. This can mislead downstream users or agents into believing sensitive or lengthy content was reduced, causing prompt-budget exhaustion, accidental disclosure of uncompressed data, or workflow decisions based on a false security/performance assumption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README promises that compression will retain all core information and explicitly forbids information loss, but it does not warn users that transforming or compressing conversation history can still affect fidelity and downstream decisions. For a skill that modifies user content and may be used for long-term memory storage, a clear caution about reviewing compressed output before reuse would be an appropriate user-facing warning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file consistently presents the skill’s description and instructions in Chinese, including the front-matter description and most operational guidance. This can violate a language/locale policy when the skill forces a specific language without giving the user an explicit choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is written entirely in Chinese, which implies a fixed language presentation without any indication that users can opt into another language or that the skill is intended only for a Chinese-speaking region. The policy for this category requires flagging language or locale constraints that are imposed without user choice or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains natural-language instructions exclusively in Chinese, which effectively constrains the skill's behavior to a specific language without documenting user choice or opt-in. Under the language/locale policy, forcing a single language without an explicit option can be a policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt forbids summarization and information loss, yet later instructs the model to compress older dialogue to key conclusions and delete process Q&A. This internal contradiction makes behavior unpredictable and encourages the model to rationalize lossy reductions, increasing the chance that important reasoning, exceptions, or safety caveats are omitted.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt claims lossless semantic compression, but the special rule for older dialogue explicitly permits dropping process exchanges and keeping only conclusions, decisions, and key information. In practice this is summarization behavior and can remove nuance, constraints, uncertainty, or prior safety-relevant context, causing downstream agents to act on an incomplete history while believing fidelity was preserved.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s natural-language description and the embedded compression prompt are entirely in Chinese, directing the model behavior in a specific language without offering the user any language or locale choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation and example invocation are entirely in Chinese, and the usage example instructs users to invoke the skill with a Chinese phrase only. This can be a language policy issue when a skill implicitly requires a specific language without documenting alternatives or making language selection optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.