Back to skill

Security audit

pastoral care德育-Katherine

Security checks for vulnerabilities and agentic risk

Overview

This skill is a school pastoral-care guide, but it gives staff sensitive minor-record and dormitory-search guidance without enough privacy, legal, or access-control safeguards.

Review carefully before installing or using in a real school. Treat it as general guidance only, and do not use its dossier, reporting, dormitory inspection, or access-permission advice unless it is rewritten to require approved school policy, local legal compliance, documented authorization, least-intrusive searches, role-based access, audit logs, retention/deletion rules, and safeguards for minors' sensitive information.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/scenarios.md:414
Finding

Intrusive Dormitory Searches and Excessive Physical Access Recommendations

Content
View full analysis

Vulnerability Details

File Location: references/scenarios.md:414-421, references/scenarios.md:459-463
Vulnerability Type: Recommendations that exceed least-privilege physical-access boundaries
Risk Level: High

Complete Vulnerable Snippets

Faithful English rendering of references/scenarios.md:414-421:

markdown
### Surprise Inspection Procedure
- Frequency: Once or twice per week, without fixed dates, to prevent students
  from learning the schedule and hiding phones in advance.
- Personnel: Male teachers inspect male dormitories and female teachers inspect
  female dormitories. At least two teachers of the same gender must be present.
- Key areas: Dormitory rooms, including cabinet gaps, exterior air-conditioning
  units, toilets, and personal belongings.
- Follow-up: When an unauthorized phone is found, apply the prescribed
  consequences and obtain the student's acknowledgment.

### Common Concealment Methods
Students may hide phones in cabinet gaps, exterior air-conditioning units, or
toilet compartments, or ask friends to store them. Devices such as smart
earphones that provide phone-like functionality may also be used.

Faithful English rendering of references/scenarios.md:459-463:

markdown
- Access-control adjustment: Female teachers cannot currently use their access
  cards to enter female dormitories for management, while male teachers cannot
  enter female dormitories for inspections. Access permissions should be
  coordinated to support inspection work.

### Recommendations for Homeroom Teachers
1. Formally report dormitory staff performance issues through school management.
2. Ask the school to modify access permissions so female teachers can enter
   female dormitories for management.
3. Until the issue is resolved, assign female homeroom teachers or female
   residential staff to manage female dormitories.
4. Record specific cooperation problems for escalation to management.

Technical Analysis

The S ...[truncated 2390 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, documented authorization under applicable law and approved school policy before any search.
  2. Limit searches to a specific incident, student, location, object, and time window.
  3. Prohibit blanket inspection of personal belongings without an appropriate case-specific basis.
  4. Require student and guardian notice or consent wherever applicable, with a documented emergency exception.
  5. Use temporary, role-based door permissions that expire automatically after the authorized activity.
  6. Log every access-permission grant, door entry, search participant, searched area, item handled, and outcome.
  7. Retain the two-person and same-gender safeguards, but supplement them with an independent authorization and oversight process.
  8. Define prohibited search areas and procedures for handling unrelated property or information.
  9. Establish inventory, chain-of-custody, return, complaint, and appeal procedures for seized devices.
  10. Replace the current broad instructions with policy-neutral guidance directing users to authorized safeguarding personnel.

T09 · Insecure Skill Coding Practices

Warning
Location
references/core.md:67
Finding

Sensitive Student Dossiers Are Recommended Without Data-Protection Controls

Content
View full analysis

Vulnerability Details

File Location: references/core.md:67-80, references/scenarios.md:380-385, SKILL.md:175
Vulnerability Type: Insecure handling guidance for sensitive information about minors
Risk Level: Medium

Complete Vulnerable Snippets

Faithful English rendering of references/core.md:67-80:

markdown
## Core Fields for Each Student's Record

- Basic information | Family circumstances | Academic status | Behavioral records
  | Emotional condition
- Dormitory status | School-family communications | Risk level | Support actions
  | Next follow-up time
- Warning triggers

Recording principles: Prioritize facts, minimize subjective judgments, include
dates, identify responsible persons, specify next steps, and support handover
and review.

Follow-up format:
[Follow-up date] [Follow-up method] [Responsible person]
[Student status] [Guardian status] [School actions]
[Risk level] [Next follow-up] [Notes]

Faithful English rendering of references/scenarios.md:380-385:

markdown
## 28. Individual Student Record

Definition: This is not merely an accumulation of documents; it is a student
growth-support system.

Core fields: Basic information, family circumstances, academic status,
behavioral records, emotional condition, dormitory status, school-family
communications, risk level, support actions, next follow-up time, and warning
triggers.

Recording principles: Prioritize facts, minimize subjective judgments, include
dates and responsible persons, specify next steps, and support handover and
review.

Faithful English rendering of SKILL.md:175:

markdown
| Emotional fluctuations that are not yet obvious | Attention | Enter them in the individual student record |

Technical Analysis

The Skill recommends creating centralized records containing sensitive data about minors, including emotional condition, family circumstances, behavior, residential status, risk classifications, and communications with guardians. ...[truncated 2626 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define the exact safeguarding or educational purpose and lawful basis for every collected field.
  2. Remove optional fields unless they are demonstrably necessary for that purpose.
  3. Require an approved student-information or safeguarding system rather than spreadsheets, chat platforms, personal devices, or general-purpose AI services.
  4. Apply role-based, least-privilege access and periodic access reviews.
  5. Encrypt records both at rest and in transit.
  6. Maintain tamper-evident logs for viewing, creation, modification, export, and deletion.
  7. Establish field-specific retention periods and automatic secure deletion.
  8. Provide procedures for correcting inaccurate records and reviewing subjective risk labels.
  9. Require appropriate notice and consent, subject to documented safeguarding and legal exceptions.
  10. Prohibit copying identifiable student records into third-party AI tools unless an approved data-processing agreement and technical protections are in place.
  11. Define breach detection, reporting, containment, notification, and recovery procedures.
  12. Separate highly sensitive emotional or safeguarding records from routine academic and disciplinary records.
  13. Use pseudonymous identifiers where direct identification is unnecessary.
  14. Train staff to record verifiable observations rather than speculative diagnoses or stigmatizing labels.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are broad and map to common school-management and student-support topics, so the skill may activate in conversations where the user did not intend to invoke this specialized workflow. In a school context, unintended activation can steer routine discussions into disciplinary or risk-framing guidance, causing privacy overcollection, inappropriate escalation, or misleading authoritative advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The emergency trigger mandates immediate activation whenever sensitive words like self-harm, suicide, violence, or sexual assault appear, without requiring contextual confirmation. This can cause false emergency routing from hypothetical, educational, quoted, or third-party discussion, which is especially risky in a pastoral-care skill because it may prompt premature reporting guidance, mishandling of sensitive disclosures, or unnecessary collection of highly sensitive student information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The '一生一档案' section instructs staff to collect and persist highly sensitive student information, including family situation, emotional state, risk level, and warning triggers, but provides no safeguards on consent, access control, retention, or sharing limits. In a school setting, this can lead to over-collection, unauthorized disclosure, stigmatization, and noncompliant handling of minors' sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dormitory phone-inspection guidance recommends surprise searches of rooms and personal belongings, including concealed areas, without any privacy, proportionality, documentation, or student-protection warning. Because this skill targets school staff managing minors, such guidance can normalize intrusive searches, create legal and safeguarding exposure, and be misused to invade privacy or selectively target students.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code presents all user-facing help and command output in Chinese only, including the module description and printed CLI text. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all guidance and role definitions exclusively in Chinese, and there is no natural-language indication that users may choose another language or that the skill is restricted to a Chinese-speaking context. Under the policy rule for language/locale constraints, forcing a single language without user opt-in can be a violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.