Back to skill

Security audit

Free Models for Russian Users

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Russian-language reference guide for free AI model providers and does not contain executable behavior or hidden access requests.

Before using the guide, verify that provider availability, free tiers, rate limits, and legal or terms-of-service requirements are current. Treat the SiliconFlow registration URL as a possible referral link, and only paste your own API key into configuration you understand.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The description and title explicitly frame the skill for Russian-speaking users and Russia ("русскоязычных пользователей", "для РФ"). This is a natural-language locale constraint, but the file does not indicate that the user can choose another language or that the restriction is required for a region-specific compliance purpose.

Static analysis

No suspicious patterns detected.