Back to skill

Security audit

AI GEO content generator

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly transparent text-generation skill, but it needs review because it gives conflicting privacy disclosures about sending supplied brand materials to an AI service.

Review before installing if your brand knowledge base includes confidential strategy, customer data, unreleased product details, or regulated information. Remove secrets and sensitive personal or business data, confirm which model provider will process the content, and manually review all generated drafts before publishing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
prompts/knowledge_base_reader.md:6
Finding

Untrusted Knowledge-Base Content Is Not Isolated from Model Instructions

Content
View full analysis

Vulnerability Details

File Location: prompts/knowledge_base_reader.md:6-9 and prompts/knowledge_base_reader.md:124-129
Vulnerability Type: Prompt injection through untrusted document content
Risk Level: Medium

Relevant Source Excerpt

The following is an English translation of the relevant prompt text:

markdown
Your tasks are:
1. Parse the user-provided brand knowledge-base file in JSON, Markdown, or YAML format.
2. Extract all key fields.
3. Check field completeness and mark missing items.
4. Output a structured field summary for downstream content-generation modules.

## Strict Constraints

1. Extract only; do not complete: During reading, extract only information actually present in the knowledge base and do not add AI-generated guesses.
2. Mark missing fields: Mark every field not found in the knowledge base as `[To Be Confirmed]`; do not fill it through guessing.
3. Preserve the original text: Preserve the brand's original wording during extraction and do not adjust tone or style at this stage.

Technical Analysis

The Skill accepts user-controlled JSON, Markdown, or YAML and forwards extracted content into downstream generation prompts. The reader requires preservation of original wording but does not state that embedded instructions, role declarations, tool requests, or prompt-control text must be treated exclusively as untrusted data.

Consequently, a malicious or compromised knowledge-base document can include instructions such as requests to ignore the generation constraints, append unrelated promotional material, conceal compliance warnings, or falsify the quality-check result. Preserving such text increases the chance that downstream model processing interprets it as an instruction rather than brand data.

This is an insecure prompt-composition practice. The audit found no delimiter policy, instruction hierarchy statement, prompt-injection detection, sche ...[truncated 1349 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add an explicit instruction that all knowledge-base content is untrusted data and that no instructions found inside it may be followed.
  2. Place document content inside clearly marked delimiters and state that delimiter contents cannot change system, Skill, safety, or output-format instructions.
  3. Parse JSON and YAML using a strict schema and allowlist only documented fields and scalar value types.
  4. Reject or flag instruction-like content, role declarations, hidden HTML comments, zero-width characters, encoded payloads, and requests to use tools or disclose context.
  5. Normalize extracted values into a structured data object before passing them to generation modules.
  6. Require downstream prompts to use extracted values only as factual source material, not as executable instructions.
  7. Add adversarial tests containing prompt injection in every accepted input format and verify that generated content does not follow it.
  8. Run the quality check in a separate context using sanitized content so compromised generation output cannot control its own assessment.

T09 · Insecure Skill Coding Practices

Note
Location
README.md:219
Finding

Privacy Statements Contradict the Disclosed External Model Data Flow

Content
View full analysis

Vulnerability Details

File Location: README.md:219-224, SKILL.md:278-281, and examples/example_website_faq.md:97-99
Vulnerability Type: Misleading privacy and external data-transmission disclosure
Risk Level: Low

Relevant Source Excerpts

The following is an English translation of README.md:219-224:

markdown
## Security and Privacy Statement

1. This Skill performs text generation and content structuring.
2. This Skill contains no executable scripts.
3. This Skill does not proactively read the user's local files.
4. This Skill processes only brand materials actively supplied by the user.
5. This Skill does not collect, upload, or externally transmit user data.
6. Do not provide passwords, private keys, API keys, cookies, tokens, identity documents, or bank-card information.

The materially equivalent no-transmission claim also appears in SKILL.md:278-281.

However, examples/example_website_faq.md:97-99 states:

markdown
### Q: How is the data processed after a brand knowledge base is supplied?

A: FrameAI connects to the user-configured large-model API through the OpenClaw framework for content generation. The supplied brand knowledge-base content is sent to the corresponding AI service. Users should not include unsanitized sensitive user data or highly confidential business documents in the knowledge base.

Technical Analysis

The primary README and Skill documentation state that user data is not uploaded or externally transmitted. The example FAQ states that supplied knowledge-base content is sent to the configured AI service. These representations cannot both accurately describe the same processing flow.

Brand knowledge bases may contain confidential positioning, product-roadmap details, internal messaging, customer information, or other proprietary business material. A user relying on the stronger no-transmission claim may provide inform ...[truncated 1343 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the no-upload claim with an accurate statement that user-supplied content may be transmitted to the configured model provider for generation.
  2. Apply the corrected disclosure consistently across README.md, SKILL.md, examples, and any user-facing intake prompt.
  3. Explain that retention, training use, geographic processing, and access controls depend on the selected provider and account configuration.
  4. Warn users before processing that confidential or personal data should be removed, minimized, or anonymized.
  5. Obtain explicit confirmation before transmitting documents marked confidential or containing potentially sensitive fields.
  6. Document whether local-only model configurations are supported and distinguish their data flow from hosted API configurations.
  7. Avoid categorical privacy guarantees unless they are enforced and verified by the execution framework.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document is written entirely in Chinese, including headings, findings, and operational guidance, without offering an alternate language or stating that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context. This creates a natural-language locale constraint that is not presented as opt-in or otherwise justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The only user prompt shown for selecting generation type is written in Chinese, and the overall skill instructions and examples are presented as Chinese-first without any indication that users may choose another language. This can constitute a language/locale policy issue because the skill appears to force a specific language rather than explicitly offering a language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing natural-language instructions and test expectations only in Chinese, including the title and all test case descriptions. Under the policy rule, forcing a specific language without user opt-in can be a language/locale policy violation, and the file does not state that the skill is intentionally limited to Chinese-speaking users or a China-specific deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document states its input contract entirely in Chinese and uses required Chinese field descriptions, which implies a fixed language/locale expectation for the skill inputs. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document prominently declares metadata in Chinese only ("最后更新时间", "版本", "状态:已合规审查") and the rest of the skill content is primarily Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains end-user skill description content entirely in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking region or audience. That creates a natural-language policy concern because it effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and body consistently define the skill as an "AI-GEO 内容自检" module and all required output examples are in Chinese, with no indication that the user may choose another language. This is a natural-language policy concern because it imposes a specific language/locale by default rather than offering an opt-in or choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hard-codes all user-facing interaction in Chinese and does not offer any language detection, negotiation, or opt-in. This can exclude or mislead users who operate in other languages, causing misunderstanding of required inputs and workflow steps; in security-sensitive or compliance-relevant contexts, that can result in incorrect operation or unsafe handling of data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language instructions, field names, and expected content are all Chinese-specific, including requirements like formal Chinese brand names and Chinese introductions. There is no indication that users may opt into another language or that the skill is intentionally restricted to a Chinese-only regional workflow, which can conflict with language/locale choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The prompt is explicitly defined as a 'Toutiao Article' generator and all instructions require producing Chinese-platform content, but the file does not state that this locale is optional or limited to a user-requested Chinese workflow. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and role definition are written as a Chinese-language FAQ generation prompt and do not indicate that another language may be selected by the user. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title and task framing specify this as a Zhihu answer generator in Chinese, which imposes a language/locale requirement. Under the policy, locale constraints should either be user-selectable or clearly documented as justified; this file does not explicitly provide either within the prompt text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template forces a specific language/locale for all generated content through its headings, guidance, and examples. Under the policy, language constraints should either be optional for the user or clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template hard-codes Chinese for all headings, questions, answers, and notices. Under the policy for natural-language violations, forcing a specific language without user opt-in is in scope unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural-language content almost entirely in Chinese, but it does not indicate that the skill is region-specific or that users may choose another language. Per the policy criteria, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states '语言: 中文为主,关键术语保留英文', which sets a default language policy in natural language. Under the policy rule, forcing a specific language without offering the user a language or locale choice is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is entirely presented in Chinese starting from the title, and nowhere indicates that language selection is optional or limited to a China-specific/regional use case. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file describes reading user-supplied JSON/Markdown/YAML brand knowledge bases and extracting structured fields for later use, including company identity, customer groups, compliance boundaries, FAQ, and standard messaging. Because the skill handles potentially sensitive business data and explicitly routes the extracted summary into a later generation flow, a user-facing warning about data handling or downstream use is absent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This template includes English headings such as 'What this brand does', 'Main users', and 'Compliance' while the body guidance is written in Chinese. That imposes a mixed-language format without any user opt-in or documented locale requirement, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.