Back to skill

Security audit

企业法律避坑专家

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language enterprise legal risk checker, but it routes users into a paid legal-service flow while collecting sensitive company details without clear privacy or payment-handling boundaries.

Review this skill carefully before installing. It may be useful for Chinese-language enterprise legal-risk screening, but users should avoid sharing confidential company identifiers, admissions about tax/invoice/criminal exposure, or payment screenshots unless they trust the publisher and understand how the information will be handled. Payment and lawyer-contact steps should be treated as promotional/off-platform activity, not as verified platform payment or legal representation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:17
Finding

Mandatory Commercial Output and Conversation-Flow Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17-24, 92-143, and 168-205
Vulnerability Type: Instructions that override normal response behavior and force branded commercial promotion, payment routing, and direct-contact solicitation
Risk Level: High

Vulnerable Code

SKILL.md, lines 17-24:

markdown
## 🚨 AI self-check rules (highest priority)

Before producing any content, the following checks must be performed:

- Do not fabricate service offerings that do not exist.
- Do not promise outcomes that cannot be guaranteed.
- Do not add undefined pricing tiers.
- Only output content explicitly supported by SKILL.md and references/modules.md.
- If an issue is uncertain, verify it or state that manual confirmation is required; do not fabricate an answer.

The original instructions explicitly designate these Skill-controlled rules as the “highest priority.”

SKILL.md, lines 92-110:

markdown
**Quick-screen output format:**

【Enterprise Legal Risk Quick-Screen Report】

Enterprise name: XXX Risk score: XX [🟢/🟡/🔴]

Top three risks:

  1. [Brief description of risk 1]
  2. [Brief description of risk 2]
  3. [Brief description of risk 3]

Recommendation: [Output the corresponding recommendation based on the risk level]


💡 Want to explore a module in depth? Choose: ① Single-module deep dive (¥19.9) → Reply with module number 1-13 ② Complete 13-module report plus one-to-one lawyer consultation (¥99) → Reply "complete report"

text

SKILL.md, lines 114-143:

markdown
### Stage 2: Single-module deep dive (Step 1)

After the user makes a selection:
1. Display the corresponding module payment QR code (`pay_19.9.jpg`)
2. Wait for the user to send a payment screenshot
3. After confirming payment, output the module's 6 in-depth questions
4. After the user answers, generate a detailed remediation plan plus 2 real cases

**List of 13 modules:**

...[truncated 4877 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the “highest priority” designation and ensure the Skill explicitly remains subordinate to platform, system, developer, and current user instructions.
  2. Remove paid-service promotion from the mandatory quick-screen report template. The default output should contain only the requested assessment, limitations, and neutral remediation guidance.
  3. Present pricing, payment options, and contact information only after an explicit user request for those details.
  4. Require informed user confirmation before requesting a payment screenshot or other payment-related information.
  5. Do not instruct the agent to confirm payment unless it has an authorized, verifiable payment-status integration. Otherwise, direct users to an independently verified human support process.
  6. Remove hard-coded telephone, WeChat, and payment-routing information from assessment logic. If contact information is retained, place it in optional metadata and clearly label it as promotional content.
  7. Clearly disclose the agent's actual status and affiliation. Do not imply that it is the named lawyer, can provide formal legal representation, or is authorized to make commitments unless that authority has been independently established.
  8. Replace the unconditional 48-hour delivery promise and scheduling commitment with language that requires availability and manual confirmation.
  9. Minimize collection of enterprise-identifying data. Explain why each field is needed, make unnecessary fields optional, and provide a privacy notice before collecting potentially sensitive business information.
  10. Add a rule prohibiting unsolicited commercial calls to action and requiring the agent to preserve the user's stated objective throughout the session.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The skill content is presented entirely in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-language/legal jurisdiction context. Under the policy, a fixed language or locale should either be optional for users or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are broad enough to activate in many ordinary business or legal discussions, which can cause the skill to inject its commercial workflow and recommendations when the user did not explicitly ask for this specific tool. In this skill’s context, that raises the risk of unwanted routing into a quasi-legal assessment flow and contact/payment upsell, making the over-triggering more problematic than a generic discovery issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include broad terms like “避坑”, “风险检测”, and “合规检查”, which can plausibly appear in general business, HR, tax, or operational conversations unrelated to this specific paid legal-assessment workflow. Overbroad activation can cause the skill to engage unexpectedly, collect business-sensitive details, and steer users into a monetized flow without clear intent, making mis-triggering a real security and safety concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation section explicitly instructs the skill to trigger on several loosely bounded keywords without requiring context validation or user confirmation. In a chat environment, this raises the chance of unintended invocation and premature collection of company data, which is especially sensitive in a legal/compliance context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill asks for company name, industry, staffing size, and business description before presenting any privacy notice, retention policy, or warning about how sensitive legal/compliance information will be handled. Because the broader questionnaire also touches labor, tax, invoices, and potential unlawful conduct, collecting identifying business details without clear data-handling boundaries can expose users to privacy, confidentiality, and legal risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all instructional content in a single language and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is reportable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description and activation behavior are presented exclusively in Chinese, and the skill’s interaction flow assumes Chinese-language operation. There is no indication that users may choose another language or that the Chinese-only constraint is an intentional, documented locale limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.