Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - ./references/salary_database.json
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed, mostly offline career-planning skill, but its salary and insurance-company recommendations should be treated as advisory and independently verified.
Install only if you want a Chinese-language career-planning assistant that may ask for education, preferences, career goals, and location. Keep optional email, subscription, memory, and live-search integrations disabled unless you explicitly need them. Independently verify salary figures and any insurance-company recommendations before acting on them.
Referenced artifact was not completely inspected
- ./references/salary_database.json
Referenced artifact was not completely inspected
- ./references/salary_database.json
Referenced artifact was not completely inspected
- ./references/salary_database.json
The '中华联合财险' record cites unrelated materials about '中华' and China generally, contradicting the claimed insurer identity while still presenting the entry as verified. This is dangerous because consumers or automated selection logic may rely on fabricated or mismatched provenance when presenting insurer recommendations.
The verified entry for '人保健康' is backed by source URLs and snippets about the People's Republic of China rather than the insurer itself, which means the dataset falsely represents provenance and verification status. In a skill that recommends or ranks insurers, this can mislead downstream logic and users into trusting incorrect entity data as regulator-verified.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
def _run(args, env_extra=None, timeout=30):
env = os.environ.copy()
env["LANG"] = "C.UTF-8"
if env_extra:
env.update(env_extra)
The activation description includes very broad everyday phrases such as career advice, choosing a major, job suggestions, and transition guidance, which can cause the skill to trigger in situations where the user did not intend to invoke this specialized workflow. Unintended activation can lead to unnecessary collection of personal profile information and steer users into embedded business flows such as insurance recommendations, increasing privacy and manipulation risk even without overtly malicious code.
The skill description and instructions are written as Chinese-only behavior and present the assistant as operating in Chinese by default, while language choice is only mentioned later as an optional integration for English reports. This creates a locale policy concern because the skill does not clearly offer users a language choice up front or justify a Chinese-only restriction.
The file’s user-facing assessment instructions and prompts are exclusively in Chinese, which imposes a specific language on users. Under the policy, language constraints should either offer user opt-in/choice or be clearly documented as a justified region-specific limitation.
This markdown file presents all skill content in a single language, Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. The policy explicitly calls for flagging language or locale constraints when they are forced without user opt-in or justification.
This markdown file contains user-facing instructions and dialogue flow exclusively in Chinese, but does not indicate that the skill is region-specific or provide any user opt-in for language selection. That can violate language/locale policy requirements when users may expect language flexibility.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"source_urls": [
"https://zhuanlan.zhihu.com/p/20258519416",
"https://www.kunlunhealth.com.cn/artdetailNew/283",
"https://data.eastmoney.com/gdfx/shareholder/76080009.html",
"https://www.qcc.com/cmainmember/140d38d0c0420d8fd968a26e71ace3df"
],
"source_url": "https://zhuanlan.zhihu.com/p/20258519416",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"source_urls": [
"https://zhuanlan.zhihu.com/p/20258519416",
"https://www.kunlunhealth.com.cn/artdetailNew/283",
"https://data.eastmoney.com/gdfx/shareholder/76080009.html",
"https://www.qcc.com/cmainmember/140d38d0c0420d8fd968a26e71ace3df"
],
"source_url": "https://zhuanlan.zhihu.com/p/20258519416",
The file's natural-language instructions and prompts are fully Chinese-language, and there is no indication that the user can choose another language or that Chinese is a justified locale-specific requirement. This can violate a language/locale policy when the skill is presented to users without explicit opt-in.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
env["LANG"] = "C.UTF-8"
if env_extra:
env.update(env_extra)
return subprocess.run(
["python3", SCRIPT] + args,
capture_output=True, text=True, timeout=timeout, env=env, cwd=SKILL_DIR,
)
This markdown file contains user-facing guidance exclusively in Chinese and does not indicate that language selection is optional or configurable. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
This markdown file presents all user-facing content in a single language with no indication that the user can choose another language or that the content is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
This markdown file uses only Chinese-language headings and content, which can amount to a language/locale policy issue if users are not given any opt-in or alternative language option. The policy specifically calls for flagging skills that force a specific language without user choice or documented justification.
The document presents all user-facing content in Chinese and does not mention that the skill is China-specific or that users may choose another language. This can violate language/locale policy expectations when a skill is not explicitly limited to a Chinese-speaking audience.
This markdown file uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for language or locale constraints, forcing a single language without opt-in can be a natural-language policy issue.
This markdown file presents all guidance exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the natural-language policy criteria, forcing a specific language without user choice can be a locale-policy issue.
This JSON is predominantly Chinese, but several company descriptions and metadata fields elsewhere in the file switch to English prose. For a skill reference file, forcing mixed-language output without any stated locale preference can violate language/locale policy because users are not given a choice or opt-in.
Descriptions such as the one at this line are written in English while surrounding records are in Chinese, and the file provides no documented language-selection policy. This can cause the skill to surface a language the user did not request, which is a locale-policy issue under the natural-language rules.
This entry uses English narrative text in a dataset that otherwise targets Chinese insurance companies and largely uses Chinese labels/content. Without an explicit opt-in or locale field, the skill may present English content unexpectedly to users.
The description is written in English despite the broader file being Chinese-oriented and lacking any stated bilingual policy. That creates a language-selection mismatch that can cause non-user-requested output language changes.
No suspicious patterns detected.