Back to skill

Security audit

Business Management Master Expertise Matrix

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language business strategy advisory toolkit with local, user-directed Python helpers and no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install this if you want a Chinese-language business strategy and management analysis toolkit. Treat outputs as heuristic consulting support, not professional investment, legal, or financial advice, and review any result before using it for important business decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (28)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This markdown file presents all user-facing instructions and usage guidance in Chinese, but does not indicate that the user may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is justified or optionality is offered.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file-level docstring is written entirely in Chinese and presents the interface contract and responsibilities only in that language. This creates a natural-language locale constraint without any indication of user opt-in or a documented region-specific justification, matching the policy-violation criteria for forced language/locale behavior.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The module header, contract metadata, descriptions, warnings, and user-facing recommendation strings are all written in Chinese, and there is no indication that the user can choose another language. Under the stated policy, a skill that implicitly enforces a specific language without opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file title and all operative instructions are written exclusively in Chinese, indicating the skill is intended to run in a fixed language/locale. The policy for this audit flags skills that force a specific language without offering user choice or documenting a justified regional constraint.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
This markdown file contains the skill's operational instructions solely in Chinese, including role, trigger scenario, input, output, and debugging guidance. Because the file does not indicate that language selection is optional or region-specific, it appears to impose a specific language/locale without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The entire prompt is written as a Chinese-only template and does not offer any user language or locale selection. This creates a language policy concern because the skill appears to constrain interaction language without explicit user opt-in or documented justification.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The listed trigger scenarios such as '持续增长瓶颈', '组织转型', and '卓越企业诊断' are high-level business situations rather than specific invocation conditions. The file does not define what qualifies or does not qualify for activation, which could cause unintended matching across many ordinary business discussions.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The file is written entirely in Chinese and the role/style instructions imply the skill operates in Chinese by default, but there is no indication that users may choose another language or that the locale restriction is required for a region-specific purpose. This can violate language/locale policy when a skill enforces a specific language without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The entire prompt is written in Chinese and provides no indication that users may choose another language or locale. Under the policy rule for language/locale constraints, this is a natural-language policy issue unless the skill explicitly offers opt-in or documents a justified region-specific limitation.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file title and all prompt instructions are written in Chinese, which strongly indicates the skill is intended to operate in Chinese only. There is no natural-language statement offering a language choice or explaining that the skill is region-specific, so this creates a language/locale policy concern under the stated rule.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The prompt content is entirely Chinese-oriented and does not provide a language selection mechanism or justify a locale restriction. This can cause mismatches between user language and model behavior, reducing transparency and reliability, and in some agent pipelines may lead to misrouting, misunderstanding, or inaccessible output for users expecting another language.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are broad and loosely defined, so the skill may activate in situations beyond its intended scope, including ambiguous business or strategic discussions. Over-broad activation increases the chance of inappropriate routing, low-quality advice, or accidental application of this persona-driven workflow where a different skill or stronger safeguards should apply.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The file presents the skill entirely in Chinese and the role description specifies communication style without offering the user a language choice. Under the policy for natural-language violations, forcing a specific language or locale without opt-in is reportable unless the constraint is clearly justified, which is not documented here.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The module name, interface contract descriptions, validation messages, and top-level docstring are all written in Chinese, indicating the skill is designed to communicate in a fixed language. The file does not provide any opt-in, locale selection, or justification for restricting outputs to Chinese, which matches the language/locale policy violation criteria.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The module name, description, parameter descriptions, and user-facing strings are all written exclusively in Chinese, which indicates a fixed language/locale experience. The file does not offer any user language choice or explain that the skill is intentionally region- or locale-specific, so this is a natural-language policy concern under the locale-choice rule.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The module name, description, interface text, and user-facing outputs are written exclusively in Chinese, indicating the skill is intended to operate in a fixed language. The file does not offer a language choice or explain a justified region-specific requirement, which creates a natural-language locale policy concern.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The module name, description, parameter descriptions, and overall contract are written entirely in Chinese, which implies a fixed language experience for users. The file does not provide any opt-in, locale selection, or justification that this is a region-specific skill, so it risks violating language/locale policy requirements.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The file’s natural-language interface, module name, comments, and docstring are entirely in Chinese, and the contract descriptions and runtime warnings later in the file continue this pattern. There is no indication that the skill supports user language selection or that it is intentionally limited to a Chinese-speaking or region-specific context, which can violate language/locale policy requirements.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The module header, docstring, parameter descriptions, and user-facing result strings are all written exclusively in Chinese, which implies a fixed language behavior. The file does not indicate that users can choose another language or that the skill is intentionally restricted to a Chinese-only/regional context.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file’s natural-language interface and usage/help text are presented entirely in Chinese, including the tool description and argument help strings. This creates a language/locale constraint without offering the user any choice or documenting that the tool is intentionally region-specific.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This code file contains natural-language documentation and CLI descriptions entirely in Chinese, including the tool description and usage help, which effectively imposes a specific language on users. The policy allows locale constraints only when user choice is offered or the constraint is clearly documented and justified, neither of which is present here.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The natural-language metadata on L004 declares '语言:Python 3.10+' as the skill's language. Under the policy for this audit, forcing a specific language or locale without user opt-in can be a natural-language policy violation, and this line does not present a choice or explain a region- or environment-specific necessity.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
The module docstring and user-visible exception text are written in Chinese, which imposes a specific language context without any visible opt-in or explanation that the skill is intentionally region-specific. This can violate language/locale policy when users or integrators are not given a choice of language.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file contains all user-facing instructions and examples in Chinese, and nowhere indicates that the user may choose another language. Under the policy rule for language or locale constraints, forcing a specific language without opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
This manifest contains multiple natural-language values entirely in Chinese, including industry descriptions, JTBD statements, decision questions, and operational labels. For a general-purpose skill artifact, forcing a specific language without offering user choice or documenting that the skill is region-specific can violate language/locale policy expectations.

Static analysis

No suspicious patterns detected.