Back to skill

Security audit

热点话题追踪

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple guide for fetching public trending-topic lists from Chinese social platforms, with no bundled code, persistence, credentials, or local data access.

Install this if you specifically want Chinese social-media and content-platform trend lookups. For ambiguous requests like 'what is trending,' expect the agent to prefer Chinese-platform results unless you ask for a different region or source.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description hard-codes Chinese-platform behavior and language context without making the locale restriction explicit as a choice for the user. In practice, this can steer the agent into returning Chinese-platform results for ambiguous 'what's trending' queries, causing user-intent mismatch, regional bias, and surprising network access to a specialized third-party service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation guidance is broad enough to trigger on many generic requests about trends, popularity, or discussions, which can cause the agent to over-select this skill even when the user did not ask for Chinese social-media hot topics specifically. This creates a scope/selection vulnerability: the agent may fetch external content unnecessarily, return locale-mismatched results, or override more appropriate skills, reducing reliability and increasing unintended data exposure to a third-party API.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.