Back to skill

Security audit

编写 Codex Goal 或 GitHub Issue

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed drafting aid for Codex goals and GitHub Issue drafts, with no executable code, persistence, or hidden data access found.

Install this if you want help turning tasks into structured Codex goals or GitHub Issue drafts. Review generated goals carefully, especially when the task involves external systems or irreversible actions, and specify your preferred output language if you do not want Chinese for ambiguous or mixed-language requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s trigger description is very broad and overlaps with ordinary writing, planning, issue drafting, and workflow assistance requests. That can cause unintended activation in contexts where the user did not actually want this skill, leading to mode confusion and potentially causing the agent to draft or structure goals/issues with incorrect assumptions or higher-authority workflow framing than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Defaulting to Chinese when the user’s language is unclear removes user choice and can produce outputs the user cannot reliably review or validate. In a security- or workflow-relevant skill, that increases the chance of misunderstanding goal contracts, authorization boundaries, or issue content before reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The language gate enforces Chinese for all ambiguous or mixed-language cases, which is a rigid policy rather than a user-directed preference. This can degrade reviewability and accuracy for copied commands or issue drafts, especially when downstream systems, collaborators, or users expect another language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and default prompt define broad uses like organizing the current task, creating or modifying issues, and selecting output modes, but they do not clearly constrain when the skill must not activate. This ambiguity can cause over-triggering in unrelated contexts, leading the agent to reshape user intent, emit workflow-specific content unexpectedly, or interfere with other skills and task routing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt hard-codes a default Chinese response preference unless the language is explicit, which can override or misread user expectations in multilingual or neutral contexts. In practice, this can cause incorrect-language outputs, reduce usability, and create policy/compliance issues where preserving user language choice is important.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document is written as normative guidance in Chinese from the title onward, and it does not offer the user a language/locale choice or explain that the skill is intentionally restricted to Chinese-speaking users. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Lines L027-L028 state that field names may remain in English and the body must be output according to output_language. Because this file is natural-language guidance and does not explain that the language choice is user-controlled or opt-in, it can be read as imposing a locale/language policy without explicit user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.