Back to skill

Security audit

AhaPoint 生成专家

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language report generator that uses browser research and saves generated reports locally, with no evidence of hidden code, credential access, or destructive behavior.

Install only if you want a Chinese-first workflow that may perform web searches and create or update local AhaPoint files. Before running it, confirm the output directory and ask the agent before overwriting or updating registry files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language instructions, examples, and workflow are entirely presented in Chinese, and the file does not state that other languages are supported or that Chinese is a deliberate, justified locale requirement. Under the policy, forcing a specific language without user opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states the skill will automatically save files and update a registry, but it does not require explicit user confirmation before modifying the local workspace. In an agent setting, silent writes can overwrite user data, create unexpected artifacts, or mutate project state in ways the user did not authorize.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description is broad enough to overlap with ordinary brainstorming, writing, and idea-formatting requests, increasing the chance that the skill activates when the user did not intend its network-research and file-writing workflow. Over-broad invocation conditions are dangerous here because the skill also includes browser use and persistent state changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example triggers include generic requests such as writing a report or recording an idea, which are ambiguous and likely to match many benign user intents outside this skill’s intended scope. In this skill, ambiguous activation is more risky because it can lead to unintended browsing, structured metadata generation, and persistent file creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The metadata template hard-codes language: "zh-CN", which imposes a specific language/locale on outputs. The document does not state that this is optional, user-selectable, or justified as a region-specific tool, so it conflicts with the requirement not to force a locale without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a report-generation assistant, but its workflow also instructs persistent writes to a project directory and mutation of a registry index. This creates side effects beyond the user-visible task, which can unexpectedly alter local state, overwrite files, or pollute repositories if the skill is invoked in a broader workspace context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

All user prompts, instructions, and examples in the skill are presented in Chinese, and the workflow assumes Chinese-language interaction by default. There is no statement that the user may choose another language, nor any documented reason that the skill must be Chinese-only, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the agent to save generated content to a fixed local filesystem path in the user's workspace without an explicit consent or safety check. This can cause unintended file writes, overwrite existing content, or create persistence side effects, especially because the workflow frames file generation as a standard automatic step rather than an opt-in action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The workflow instructs the agent to perform browser-based network research without warning users that their prompts or topics may be sent to external services. This can expose sensitive research interests, proprietary topics, or personal data through outbound searches the user did not expect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill is presented as an AhaPoint generation expert, but the documentation also positions generated timestamps and hashes as 'priority proof' and '确权' metadata. Establishing provenance or ownership-style claims is a distinct capability from content generation and is not clearly justified by the narrow manifest wording alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s instructional and example content consistently assumes a single language locale, with no opt-in or alternative language guidance. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.