Back to skill

Security audit

Convert MD document to HTML

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple Markdown-to-HTML card formatter with local theme files and no evidence of hidden execution, data access, or persistence.

Install this if you want a Chinese-language Markdown-to-HTML card formatter. Review the generated HTML before posting it to content platforms, especially because it preserves user-provided content and emits inline-styled HTML.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and core instructions are written entirely in Chinese and define the skill role and behavior in that language, with no indication that users may choose another language. This creates a language/locale policy concern because the skill appears to enforce a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s display name and all instructional content are written in Chinese, which imposes a specific language/locale on the skill. There is no indication that users can opt into another language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file uses Chinese for the display name and all instructional content, which indicates a fixed language/locale for the skill experience. There is no visible opt-in, language selection, or documented region-specific justification, so this appears to violate the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file presents the skill display name and all instructional content in Chinese, with no indication that users can choose another language or that the theme is intentionally limited to a Chinese-speaking context. This creates a natural-language locale constraint that is not optional or justified in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The display name is specified only in Chinese ("海洋主题"), which indicates a language-specific presentation without any visible option for user choice or localization fallback. This can violate language/locale policy when a skill implicitly forces one language for all users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.