Back to skill

Security audit

Legal Gstack

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language legal workflow skill that works with local legal files, with no install scripts, executable payloads, or cloud upload behavior found.

Install only if you want a Chinese-language legal-practice workflow that stores and reads matter materials under local Documents folders. Treat all case files, client communications, conflict checks, and live-comment archives as confidential; use approved protected storage, verify generated document paths, and confirm before archiving or replacing files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (14)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The manifest description and main title/content are presented entirely in Chinese and frame the skill as a dedicated workflow suite for a specific Chinese-speaking legal practitioner. Under the policy, a language/locale constraint should not be imposed without explicit user opt-in or a clearly documented justification for the locale restriction.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly directs management and archiving of case files in local document directories but provides no privacy, access-control, or data-handling warnings. Because legal case materials commonly contain highly sensitive personal, evidentiary, and privileged information, omission of safety guidance can lead users to store, expose, or mishandle confidential data on inadequately protected local systems.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill metadata, title, functionality, and file path conventions are written entirely in Chinese, which indicates a language-specific operating assumption. There is no statement that the skill is limited to Chinese-language legal intake, nor any opt-in or alternative language support, so this creates a natural-language locale policy concern.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The natural-language description, headings, usage context, and output naming are entirely specified in Chinese, implying a fixed language/locale for the skill. The file does not mention that Chinese is optional, configurable, or required for a region-specific purpose.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The natural-language description, title, features, and usage guidance are presented exclusively in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy issue.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The manifest description and all user-facing instructions are written exclusively in Chinese, presenting the skill as operating in a single language with no opt-in or alternative locale guidance. Under the policy, a language constraint should either offer user choice or be explicitly justified as region-specific.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly specifies output paths for .docx files in user document directories but does not warn that running the skill may create or overwrite files there. In a legal drafting context, this is risky because generated documents may overwrite existing pleadings or place sensitive legal material into case folders without explicit user confirmation, causing confidentiality, integrity, or workflow issues.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The natural-language description is entirely in Chinese and presents the skill as a Chinese legal-research expert without any indication that users may interact in other languages or opt into this locale constraint. Under the policy, forcing a specific language without user opt-in is a reportable natural-language policy issue unless the restriction is clearly documented and justified.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises real-time monitoring of Douyin live comments with second-level responsiveness but provides no notice about collection, handling, retention, or disclosure of user-generated content. In a legal-services context, comment streams may contain personal data, case details, or sensitive inquiries, so the lack of privacy guidance and controls creates a meaningful compliance and confidentiality risk.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The manifest description and all user-facing instructions are written only in Chinese, which indicates the skill is effectively constrained to a specific language/locale. The file does not offer an opt-in language choice or explain that the skill is intentionally region-specific, so this is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The natural-language content, including the description, headings, and command annotations, is entirely in Chinese. This may violate language/locale policy when no user opt-in, alternative language option, or documented region-specific justification is provided.

Missing User Warnings

Low
Confidence
91% confidence
Finding
This markdown file states that output will be written to a specific path under the user's Documents directory, which affects local user data. The description does not include any warning or disclosure that the skill creates or overwrites files there.

Missing User Warnings

Low
Confidence
91% confidence
Finding
This markdown file states that output will be placed in a specific path under the user's Documents directory, which implies a file write affecting user data. The description provides no warning or note about creating files, modifying existing content, or where data will be stored beyond the path itself.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
SQP-3 covers natural-language policy violations such as forcing a specific language without user opt-in. The manifest description and all user instructions are presented only in Chinese, with no indication that users may choose another language or that the locale restriction is intentional and documented.

Static analysis

No suspicious patterns detected.