Back to skill

Security audit

Freelance Proposal Writer

Security checks for vulnerabilities and agentic risk

Overview

This is a proposal-writing helper with no executable code, persistence, credential access, or hidden behavior found.

Before installing, users should be comfortable providing freelance profile details, portfolio links, rates, and project descriptions to the agent context. Avoid including client secrets, private account data, confidential pricing arrangements, or unpublished client materials unless they are redacted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all usage guidance are presented entirely in Chinese, with no indication that other languages are supported or that the Chinese-only scope is intentional and justified. This can violate language/locale policy when users are not given an explicit language choice or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases such as '写提案', '投标', and '自由职业' that can appear in ordinary conversation, making accidental or overly broad skill activation plausible. In an agent environment, unintended invocation can cause inappropriate handling of user context or proposal/profile data even though the skill itself is not overtly malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill encourages use of personal profile details, case links, pricing, and proposal history but does not warn users about sharing sensitive or confidential information. This increases the risk that users may provide private client data, personally identifiable information, or commercially sensitive pricing/history to the skill without understanding the exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructions, feature descriptions, triggers, and usage guidance are written entirely in Chinese, which effectively forces a specific language experience. There is no indication that users may choose another language or that the Chinese-only presentation is an intentional, justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.