Back to skill

Security audit

gov-fund-application

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language advisory skill for government fund applications, with no executable code or hidden system-level behavior found.

Installers should treat this as a government-funding research aid, not legal, financial, or compliance advice. Before using its output in real submissions, verify current local rules with the relevant fund manager or government department and avoid overstating technical qualifications.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill metadata includes a long trigger list with several broad, high-frequency phrases such as government subsidy, project application, and application conditions. In an agent ecosystem, overly broad activation terms can cause the skill to trigger for loosely related conversations, leading the model to inject domain-specific guidance when the user did not intend to invoke this workflow.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction suggesting projects without real technical barriers can be 'packaged' or reframed as 'AI+industry' encourages misrepresentation to satisfy government-fund eligibility criteria. In this skill context, that is dangerous because the agent is specifically designed to guide real funding applications, so users may be nudged into deceptive statements in regulated submissions, creating fraud, compliance, and reputational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that other languages are available or that Chinese is required for a region-specific reason. Under the language/locale policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The activation guidance says to enable the skill when users ask broad questions like whether a project can get government money or which level to apply to, while also referencing a related funding-diagnosis skill. Because the boundary between this skill and adjacent funding-advice contexts is not crisply defined, an orchestrator may select it in situations better handled by another skill, producing misrouted or incomplete advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese, including headings, instructions, and decision criteria. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.