Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md | `SKILL.md` | 主规范(本文件):判断、硬约束、自检 |
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently generates local Chinese math-teaching HTML pages and does not show hidden data access, persistence, or exfiltration behavior.
Installers should understand this is a Chinese-focused local HTML generator. Use it in a normal workspace, review or choose the output path, and avoid placing generated files over important existing documents. Custom SVGs should remain static and inline as the skill instructs.
Referenced artifact was not completely inspected
| `SKILL.md` | 主规范(本文件):判断、硬约束、自检 |
Referenced artifact was not completely inspected
| `templates/learnwa-template.html` | 通用 H5 模板(含 CSS/SVG/交互/朗读) |
Referenced artifact was not completely inspected
| `templates/learnwa-template.html` | 通用 H5 模板(含 CSS/SVG/交互/朗读) |
The skill instructs the agent to read and write local files and invoke a generator script, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates a least-privilege gap: an agent runtime may grant broader filesystem capabilities than the skill actually needs, increasing the chance of unintended file access or overwrites if the skill is invoked with adversarial input or misused by the model.
The title and all instructional content are written in Chinese, and the example user inputs and expected phrasing are consistently Chinese-only. There is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context for compliance or regional reasons.
The file title and all user-facing examples and instructions are exclusively in Chinese, framing the skill format as Chinese-only usage. There is no indication that users may choose another language or that the Chinese-only constraint is justified as a region-specific requirement.
This markdown file is written entirely in Chinese and repeatedly specifies Chinese labels and UI text, including font stacks like 'PingFang SC' and 'Microsoft YaHei'. Under the policy rule for language/locale, this appears to force a specific language/locale rather than offering a user-selectable option or documenting a justified regional constraint.
This code embeds user-facing guidance, errors, prompts, and examples entirely in Chinese, and the top-level docstring explicitly says repair suggestions are provided in Chinese. Across the CLI flow, there is no option to choose another language or locale, so the skill imposes a specific language by default rather than offering user choice.
The code sets u.lang='zh-CN' for all spoken output, forcing a specific language/locale. This is a natural-language policy concern because the file provides no user opt-in or configurable language selection for speech output.
This markdown file is natural-language instructional content, and it consistently uses Chinese for headings, instructions, and parent prompts. Under the language/locale policy rule, forcing a specific language without giving the user a choice or documenting a justified locale constraint is a policy concern.
No suspicious patterns detected.