Back to skill

Security audit

Online Course Creator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local course-material generator with no evidence of hidden network access, credential use, persistence, or destructive behavior.

Install only if you want a Chinese-first course creation helper and verify the publisher before paying. Expect local generation of course materials and, if you run example.js, creation of a JSON export file under the skill directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · exports/python-data-analysis-course.json (reported line 11)May include surrounding context.

json
{
  "metadata": {
    "topic": "Python 数据分析",
    "createdAt": "2026-03-15T06:19:28.848Z",
    "version": "1.0.0"
  },
  "outline": {
    "title": "Python 数据分析完整课程",
    "subtitle": "从零到精通的系统学习路径",
    "level": "beginner",
    "levelDescription": "零基础入门,无需先修知识",
    "estimatedDuration": "24小时",
    "modules": [
      {
        "moduleNumber": 1,
        "title": "模块1: 课程介绍与学习路径",
        "description": "深入讲解Python 数据分析的课程介绍与学习路径内容",
        "lessons": [
          {
            "lessonNumber": 1,
            "title": "课程介绍与学习路径 - 第1节",
            "type": "video",
            "duration": "15分钟",
            "description": "详细讲解Python 数据分析相关知识点"
          },
          {
            "l

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · index.js (reported line 37)May include surrounding context.

js
beginner: '零基础入门,无需先修知识',
    intermediate: '需要基础概念理解,适合有一定经验者',
    advanced: '深入专业内容,需要扎实基础'
  };

  const outline = {
    title: `${topic}完整课程`,
    subtitle: `从${level === 'beginner' ? '零' : level === 'intermediate' ? '基础' : '进阶'}到精通的系统学习路径`,
    level: level,
    levelDescription: levelDescriptions[level],
    estimatedDuration: `${modules * 3}小时`,
    modules: []
  };

  // 生成模块结构
  const moduleTemplates = {
    beginner: [
      '课程介绍与学习路径',
      '核心概念基础',
      '环境搭建与工具准备',
      '第一个实战项目',
      '核心技能深入 (上)',
      '核心技能深入 (下)',
      '综合实战应用',
      '进阶方向与职业发展'
    ],
    intermediate: [
      '知识体系回顾与进阶路径',
      '高级概念解析',
      '最佳实践与设计模式',
      '性能优化技�

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing documentation and instructions in Chinese, and it does not indicate that the skill is China-specific or that users can choose another language. That can violate language/locale policy because it effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description begins in Chinese and the entire README is written in Chinese without indicating multilingual support or asking the user to opt into that locale. Per the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The advertised trigger phrases are broad, generic educational terms such as '创建课程', '课程大纲', and '视频脚本', which can overlap with many normal user requests outside a narrowly intended skill scope. This can cause unintended activation or routing, leading the agent to invoke this paid/commercial skill in contexts where the user did not clearly request it, increasing the risk of misexecution, confusion, or inappropriate data handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code's user-facing comments and console output are consistently in Chinese, including status messages and usage guidance. Under the policy, a skill should not force a specific language or locale unless it offers opt-in/choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON manifest consistently uses Chinese for titles, descriptions, scripts, quizzes, and marketing copy, beginning with the topic field at L0003. Because the file does not provide any user opt-in, alternative locale, or justification for a Chinese-only experience, it appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing descriptions and generated course content that are predominantly fixed in Chinese, indicating the skill is designed to operate in a specific language without any visible user opt-in or language-selection mechanism. The policy for natural-language violations applies to all file types, including code string literals and comments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated course outline fields such as titles, subtitles, durations, and module names are hardcoded in Chinese, and there is no parameter allowing users to select another language or locale. This forces a specific language experience on all users rather than offering a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The marketing generators produce Chinese-language copy and platform-specific content for Weibo and WeChat by default, while only one field includes English text. Because there is no explicit user choice or documented regional scope, the skill embeds a fixed locale policy in natural-language outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file is primarily written in Chinese, but the LinkedIn marketing section is presented only in English and does not indicate that language selection is optional. The policy requires flagging language or locale constraints when a skill forces a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description and usage guidance are presented in Chinese, which can impose a language expectation on users, yet the skill also includes English triggers like "online course" and "course creator". Because no user opt-in, bilingual support statement, or justified locale constraint is provided, this creates a potential language/locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description is written only in Chinese ("AI 驱动的课程创作技能"), which signals a fixed language choice without any indication that users can select another language or that the skill is region-specific. This can violate language/locale policy when no opt-in or documented justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.