Back to skill

Security audit

希沃白板原生插件开发技能

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for EasiNote native plugin development, with sensitive host-process topics disclosed and generally constrained to that purpose.

Install this if you are developing EasiNote 5 native plugins and are comfortable with guidance for in-process host APIs. Review generated plugin code carefully because native plugins can affect EasiNote UI, content, telemetry, packaging, and restart behavior; avoid including secrets, private paths, or unnecessary user data in plugin outputs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill declares extremely broad auto-trigger conditions, including use even when the user did not explicitly request it. This can cause inappropriate invocation in unrelated contexts, increasing the chance that the agent applies high-privilege, process-internal plugin guidance where it is not needed and may expose users to unsafe or irrelevant actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

L003 的自然语言描述整体以中文限定技能说明与交互预期,但未见允许用户选择其他语言或按用户语言偏好响应的说明。根据该规则,强制特定语言而无用户 opt-in 属于语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document title and instructional content are entirely in Chinese, and the file does not indicate that language selection is optional or that the skill is specifically limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

该 markdown 文件明确说明插件会“添加中文语言项”,后续多个示例也使用 zh-CHS 作为唯一语言资源。这属于自然语言层面的语言/区域策略约束,但文档未提供用户选择、回退机制,亦未说明这是特定地区限定工具。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

这里的示例代码字符串字面量直接将语言源限定为 new CultureInfo("zh-CHS"),没有任何用户 opt-in 或多语言支持说明。根据规则,代码字符串和文档中的自然语言都属于可检查范围,因此这是语言/locale 策略违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该段再次把界面文案资源限定在 zh-CHS,且周边说明没有标注这是区域特定示例,也没有指导如何让用户选择语言。重复的单语言强制会放大策略不合规风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, and there is no indication that readers can choose another language or that the content is intentionally restricted to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill documentation is written in Chinese and does not indicate that other languages are supported or that Chinese is a required, region-specific constraint. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Chinese and does not provide an alternative language option or indicate that the skill is intentionally limited to Chinese-speaking users for a documented regional or compliance reason. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The language-registration example only defines a Chinese culture entry (zh-CHS) and the surrounding guidance focuses on using that locale, without offering an opt-in or explicit user choice. Under the policy, forcing a specific language/locale in natural-language instructions can be a locale-policy issue unless the constraint is clearly justified or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.