Back to skill

Security audit

Workflow Dlc Socratic Dialogue

Security checks for vulnerabilities and agentic risk

Overview

This planning skill is mostly a normal guided-dialogue helper, but it tells the agent to save detailed project notes to disk without clear opt-in or retention controls.

Review before installing if your planning discussions may include confidential product, customer, business, or internal strategy details. Use it only if you are comfortable with the agent creating local JSON records, or modify the skill so logging is opt-in, minimized, and easy to delete.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples are very broad (e.g., 'I want to write XX', 'help me do XX', 'start XX project'), which can cause the skill to activate on many ordinary requests. Over-broad invocation can unexpectedly steer users into a gated workflow and, in this skill’s case, increase unnecessary collection and logging of planning details.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file says the skill applies to "任何从 0 到 1 的产出启动时" and lists examples, but this still leaves ambiguity around many borderline cases. Although one non-applicable case is given, the trigger scope is not constrained with explicit positive criteria or sufficient negative examples to prevent accidental invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s declared purpose is a kickoff dialogue aid, but it additionally instructs persistent disk logging of detailed session contents including goals, pain points, and project plans. This creates unnecessary data retention and potential leakage risk because sensitive planning information is stored beyond the immediate interaction without a clear operational need or consent flow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill stores rich user/project planning data that is not clearly necessary for conducting a three-step dialogue. Collecting and retaining more information than required increases privacy, confidentiality, and downstream prompt/history exposure risks if the logs are later accessed, indexed, or shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to write structured logs containing user-supplied project details, pain points, success metrics, and future plans without any user-facing disclosure that the data will be persisted. Silent persistence of potentially sensitive business context undermines user expectations and raises confidentiality and compliance concerns.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly persists natural-language planning artifacts and user pain points to timestamped files, creating a durable corpus of sensitive internal context. Such logs are prone to accidental exposure through backups, repository commits, shared workspaces, or later model ingestion, making the skill more dangerous than a purely transient dialogue helper.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language instructions, examples, and user prompts are entirely in Chinese, and the skill does not mention whether this language requirement is optional or region-specific. For a cross-role general-purpose skill, forcing one language without opt-in can violate language or locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.