Back to skill

Security audit

运用古智慧提升格局与破局之路

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese wisdom advisor, but it asks for sensitive personal and business context and instructs agents to persist user feedback into shared knowledge files.

Install only if you are comfortable with a Chinese-language advisory skill that may ask for birth/spatial/resource details and may encourage recording outcomes. Do not provide precise personal identifiers, confidential workplace or business information, or sensitive strategy details. Run it in a read-only environment unless the persistent case-log and mapping update behavior has been removed or placed behind explicit review and consent.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
KNOWLEDGE/case-log.md:24
Finding

Unvalidated User Feedback Can Poison Persistent Shared Knowledge

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:31
Finding

Mandatory Collection and Potential Persistence of Excessive Personal and Business Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (24)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly requires collecting sensitive personal data such as birth time, location/spatial details, and core resources, then using it for metaphysical profiling. This is dangerous because it solicits sensitive information without privacy notice, minimization, consent language, retention limits, or a clear necessity standard, creating avoidable privacy and profiling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file is entirely written in Chinese and states it defines the structure and depth of 'perfect responses' for the related skill, indicating the examples are intended to shape response behavior. There is no indication that users may choose another language or that the Chinese-only constraint is optional or region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The disclaimer is written primarily in Chinese and does not provide a language choice or explain a justified China-only audience restriction. Users who cannot read Chinese may miss safety, liability, and proper-use limitations, increasing the chance of misuse or uninformed reliance on the skill's outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file is written entirely in Chinese and presents the protocol as the default operating specification for the skill, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file states it defines behavior for apply-china-classics, but the provided manifest is for apply-china-wisdom. This is an active documentation-to-skill identity contradiction, creating uncertainty about whether this protocol belongs to the declared skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly instructs the AI to persistently update repository knowledge files based on user feedback, creating a self-evolution loop that exceeds a normal advisory or read-only knowledge skill. This is dangerous because it turns untrusted user input into durable instruction changes, enabling prompt injection persistence, knowledge poisoning, and drift in future behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented 'evolution protocol' grants the agent ongoing authority to modify stored mappings and indexes, which is not obviously required for a wisdom-application skill whose stated purpose is giving cultural guidance. Persistent self-modification broadens the attack surface by allowing adversarial feedback to reshape future outputs and potentially embed unsafe instructions into trusted internal files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown tells the AI to write to repository files whenever users provide feedback, but does not warn users that their input may alter stored knowledge. This is dangerous because users may unknowingly trigger persistent modifications, and attackers can intentionally plant poisoned content that affects later sessions or downstream consumers of the repository.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly states it is intended for apply-china-classics while the manifested skill is apply-china-wisdom, indicating cross-skill knowledge leakage or packaging drift. This can cause the agent to load behavior, assumptions, or routing logic not reviewed for the active skill, leading to unintended outputs and weakened security boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Mandating Chinese-language operation without user choice can bypass user expectations, consent, or platform language controls, increasing the chance of misunderstanding safety-critical guidance. In this skill, which provides interpretive advice, forced language behavior may obscure limitations and reduce user comprehension of risk-related content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains all user-facing instructions and prompts in Chinese, effectively forcing a specific language for interaction. The policy allows locale constraints only when they are optional or clearly documented as justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all operational content in a single language and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. That creates a natural-language policy concern under the language/locale rule because the skill effectively forces one locale without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file translates classical stratagems into concrete modern workplace and business tactics centered on concealment, manipulation, induced overconfidence, asset transfer, and asymmetric pressure. In this skill context, the content is not merely descriptive or historical; it is structured as an execution-oriented mapping library, which increases the likelihood of harmful real-world misuse in workplace coercion, deceptive competition, or evasion of accountability.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file provides actionable guidance for information control, power rebalancing, and indirect competitive attacks without sufficient justification tied to a safe business or educational purpose. Because the skill is presented as modern executable advice, these patterns can enable manipulative conduct against colleagues, counterparties, or competitors under the guise of cultural wisdom.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file is written predominantly in Chinese and describes operational behavior such as the trigger and decoding workflow in Chinese, without stating that users may interact in other languages or choose a locale. Under the language/locale policy rule, this can be a natural-language policy concern when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that all outputs must follow a fixed 'classical minimalist' formatting style, without indicating that users can choose a different language or presentation format. This can reduce usability, obscure safety-critical information for users who need plain or different-language output, and create avoidable misunderstandings in high-stakes advice contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger for Deep Analysis Mode covers very broad categories like life difficulties, confusion, management issues, or philosophical questions, which can match many ordinary user requests unintentionally. This increases the chance that the skill activates high-risk workflows, including sensitive data collection and speculative metaphysical analysis, without clear user consent or expectation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Creative Asset Layer is triggered by generic requests to create, continue writing, generate prompts, or build worldviews, which are common tasks and may cause the skill to overtake unrelated conversations. While less severe than data-handling issues, ambiguous activation can still lead to unintended behavior and loss of user control over response mode.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Tactical Execution Layer is triggered by broad business, workplace, and resource-competition scenarios, then directs the system to apply stratagems and psychological effects. In context, this is more dangerous because it can normalize manipulative or adversarial advice in ordinary professional situations, even though it mentions ethics checks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill mandates a specific classical minimalist output format and presentation style for all outputs, without offering user choice or opt-out. This is primarily a user-control and transparency issue: it can override user preferences and obscure whether the content is adapted to the user's needs versus the skill author's preferred aesthetic.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The simulation mode activates on vague future-prediction or path-forecasting requests and claims to produce probability-weighted outcomes through multi-agent simulation. This can mislead users into attributing unwarranted authority to speculative forecasts, especially in sensitive life or business decisions, without clear limits or disclaimers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is entirely written as a Chinese knowledge index and describes itself as the retrieval base for a skill, but it provides no indication that users may choose another language or opt in to Chinese-only behavior. Because the policy category applies to natural-language content in all file types, this is a language/locale constraint that is not explicitly optional or justified in the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

All user-facing instructional content in this file is in Chinese, and the protocol uses mandatory language such as "AI 必须执行以下流程" without indicating that the user can choose another language. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The mode includes users who want to learn how to think or improve cognition, which are broad intents common across many assistants. Although one quoted phrase is specific, the surrounding criteria still lack clear boundaries and exclusion cases.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.