Back to skill

Security audit

funding-fit-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language fundraising assessment skill that asks for project details to score funding fit and does not show hidden execution, persistence, exfiltration, or destructive behavior.

Install this only if you want a Chinese-language, China-focused fundraising assessment assistant. Treat its scores and institution matches as planning support, not legal, financial, or investment advice; verify current policy and fund information with official sources before acting, and avoid sharing confidential numbers, exact locations, or unreleased fundraising plans unless needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is authored entirely in Chinese and appears to assume Chinese-language interaction without offering user choice or declaring a locale restriction. This can cause incorrect activation or unusable outputs for users in other languages, leading to misunderstanding in a domain involving financial and legal nuance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad, conversational phrases such as asking what to do next after a project description, which can cause the skill to activate outside a clear financing-assessment intent. In an agent ecosystem, this increases the chance of unintended routing, causing oversharing of sensitive business information and bypassing a more appropriate skill or neutral assistant behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON dataset is written entirely in Chinese, including the top-level note and all user-facing descriptive fields, with no indication that language choice is configurable or limited to a China-specific deployment. Under the policy for natural-language violations, forcing a specific language without user opt-in is in scope across all file types.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains a full skill knowledge base in Chinese and does not indicate that users may request another language or locale. Under the language/locale policy rule, forcing a single language without opt-in can be a natural-language policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire handbook is presented only in Chinese and does not offer any language or locale choice. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template explicitly asks users to provide sensitive business information, financing history, equity plans, and precise registration/operating location, but it does not present any user-facing notice about data sensitivity, minimization, storage, retention, or who will see the information. In a financing-diagnosis context, these details can expose strategic plans, fundraising status, and geographic constraints, creating privacy, confidentiality, and competitive risks if mishandled or logged by the platform.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a plain-text file, so SQP-1 applies. The document presents recommendation content but does not specify when this skill should activate, what exact user requests it is meant to handle, or any exclusions/negative examples, which could lead to overly broad or unintended invocation if used as a skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file title and all user-facing changelog content are presented exclusively in Chinese, with no indication that another language is available or that the locale restriction is optional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all guidance, headings, and instructions exclusively in Chinese, with no indication that users can choose another language or that the Chinese-only scope is required for a justified regional-compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file begins with a Chinese-only title and the rest of the skill content is presented in Chinese throughout, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all user-facing content in Chinese, including instructions, checklists, and warnings, but does not indicate that the skill is China-specific or give users an option to choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

该文件是 JSON 清单类文件,适用 SQP-1。内容只给出项目评估与匹配清单,没有任何关于何时应触发该技能、何时不应触发、或排除条件的说明;如果此文件被系统用作技能配置或描述,激活范围会显得过宽且不明确。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.