Back to skill

Security audit

ai-era-career-planner

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed, mostly offline career-planning skill, but its salary and insurance-company recommendations should be treated as advisory and independently verified.

Install only if you want a Chinese-language career-planning assistant that may ask for education, preferences, career goals, and location. Keep optional email, subscription, memory, and live-search integrations disabled unless you explicitly need them. Independently verify salary figures and any insurance-company recommendations before acting on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
- ./references/salary_database.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- ./references/salary_database.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
- ./references/salary_database.json

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The '中华联合财险' record cites unrelated materials about '中华' and China generally, contradicting the claimed insurer identity while still presenting the entry as verified. This is dangerous because consumers or automated selection logic may rely on fabricated or mismatched provenance when presenting insurer recommendations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The verified entry for '人保健康' is backed by source URLs and snippets about the People's Republic of China rather than the insurer itself, which means the dataset falsely represents provenance and verification status. In a skill that recommends or ranks insurers, this can mislead downstream logic and users into trusting incorrect entity data as regulator-verified.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/test_report_exporter.py (reported line 36)May include surrounding context.

python
def _run(args, env_extra=None, timeout=30):
    env = os.environ.copy()
    env["LANG"] = "C.UTF-8"
    if env_extra:
        env.update(env_extra)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description includes very broad everyday phrases such as career advice, choosing a major, job suggestions, and transition guidance, which can cause the skill to trigger in situations where the user did not intend to invoke this specialized workflow. Unintended activation can lead to unnecessary collection of personal profile information and steer users into embedded business flows such as insurance recommendations, increasing privacy and manipulation risk even without overtly malicious code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description and instructions are written as Chinese-only behavior and present the assistant as operating in Chinese by default, while language choice is only mentioned later as an optional integration for English reports. This creates a locale policy concern because the skill does not clearly offer users a language choice up front or justify a Chinese-only restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s user-facing assessment instructions and prompts are exclusively in Chinese, which imposes a specific language on users. Under the policy, language constraints should either offer user opt-in/choice or be clearly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all skill content in a single language, Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. The policy explicitly calls for flagging language or locale constraints when they are forced without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructions and dialogue flow exclusively in Chinese, but does not indicate that the skill is region-specific or provide any user opt-in for language selection. That can violate language/locale policy requirements when users may expect language flexibility.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/insurance_broker_companies.json (reported line 618)May include surrounding context.

json
"source_urls": [
          "https://zhuanlan.zhihu.com/p/20258519416",
          "https://www.kunlunhealth.com.cn/artdetailNew/283",
          "https://data.eastmoney.com/gdfx/shareholder/76080009.html",
          "https://www.qcc.com/cmainmember/140d38d0c0420d8fd968a26e71ace3df"
        ],
        "source_url": "https://zhuanlan.zhihu.com/p/20258519416",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/insurance_broker_companies.json (reported line 1269)May include surrounding context.

json
"source_urls": [
          "https://zhuanlan.zhihu.com/p/20258519416",
          "https://www.kunlunhealth.com.cn/artdetailNew/283",
          "https://data.eastmoney.com/gdfx/shareholder/76080009.html",
          "https://www.qcc.com/cmainmember/140d38d0c0420d8fd968a26e71ace3df"
        ],
        "source_url": "https://zhuanlan.zhihu.com/p/20258519416",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file's natural-language instructions and prompts are fully Chinese-language, and there is no indication that the user can choose another language or that Chinese is a justified locale-specific requirement. This can violate a language/locale policy when the skill is presented to users without explicit opt-in.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_report_exporter.py (reported line 40)May include surrounding context.

python
env["LANG"] = "C.UTF-8"
    if env_extra:
        env.update(env_extra)
    return subprocess.run(
        ["python3", SCRIPT] + args,
        capture_output=True, text=True, timeout=timeout, env=env, cwd=SKILL_DIR,
    )

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese and does not indicate that language selection is optional or configurable. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all user-facing content in a single language with no indication that the user can choose another language or that the content is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses only Chinese-language headings and content, which can amount to a language/locale policy issue if users are not given any opt-in or alternative language option. The policy specifically calls for flagging skills that force a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document presents all user-facing content in Chinese and does not mention that the skill is China-specific or that users may choose another language. This can violate language/locale policy expectations when a skill is not explicitly limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for language or locale constraints, forcing a single language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all guidance exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the natural-language policy criteria, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This JSON is predominantly Chinese, but several company descriptions and metadata fields elsewhere in the file switch to English prose. For a skill reference file, forcing mixed-language output without any stated locale preference can violate language/locale policy because users are not given a choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Descriptions such as the one at this line are written in English while surrounding records are in Chinese, and the file provides no documented language-selection policy. This can cause the skill to surface a language the user did not request, which is a locale-policy issue under the natural-language rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This entry uses English narrative text in a dataset that otherwise targets Chinese insurance companies and largely uses Chinese labels/content. Without an explicit opt-in or locale field, the skill may present English content unexpectedly to users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is written in English despite the broader file being Chinese-oriented and lacking any stated bilingual policy. That creates a language-selection mismatch that can cause non-user-requested output language changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.