Back to skill

Security audit

金字塔原理逻辑教练

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Markdown-based writing and logic-coaching skill with no executable runtime, credential use, telemetry, or hidden privileged behavior found.

Reasonable to install if you want a Chinese-first Pyramid Principle writing coach. Be aware that broad phrases like “help me organize my thoughts” may trigger it in some agents, so invoke it explicitly when working with sensitive drafts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 185)May include surrounding context.

html
</div>
</div></nav>

<!-- Hero -->
<section class="hero"><div class="container">
<div class="hero-badge"><span class="dot"></span><span data-en="v1.2.0 · Open Source · Based on《The Pyramid Principle》by Barbara Minto" data-zh="v1.2.0 · 开源发布 · 基于 Barbara Minto《金字塔原理》">v1.2.0 · 开源发布 · 基于 Barbara Minto《金字塔原理》</span></div>
<h1><span data-en="Pyramid Principle Logic Coach:<br>No theory — just <em>diagnose &amp; rebuild</em>." data-zh="金字塔原理逻辑教练:<br>不教理论,只管<em>诊断和重建</em>。">金字塔原理逻辑教练:<br>不教理论,只管<em>诊断和重建</em>。</span></h1>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 253)May include surrounding context.

html
</div>
</div></section>

<!-- Core Highlights -->
<section class="block bg-warm" id="highlights"><div class="container">
<div class="section-label">✨ <span data-en="Core Highlights" data-zh="核心亮点">核心亮点</span></div>
<h2 class="section-title"><span data-en="Six capabilities that turn messy drafts into airtight pyramids" data-zh="六项能力,把散乱草稿变成密不透风的金字塔">六项能力,把散乱草稿变成密不透风的金字塔</span></h2>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises trigger phrases such as 'help me organize my thoughts' and similar broad, everyday wording that can overlap with many unrelated user requests. In agents that auto-select skills based on fuzzy matching, this can cause unintended invocation, leading the skill to intercept content the user did not explicitly intend to route through this logic-coaching workflow.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 190)May include surrounding context.

bash
git clone https://github.com/muippt/mu-pyramid-principle.git ~/.claude/skills/mu-pyramid-principle

Using a different agent? Just drop the folder wherever your tool loads skills from. Project-level works too: .claude/skills/mu-pyramid-principle.

2. Verify — restart your agent and confirm the skill is picked up

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README says pasted text will receive 'automatic logic diagnosis + pyramid rebuild' without defining clear boundaries for what kinds of pasted text should activate the skill. In an auto-routing environment, vague activation criteria increase the chance that sensitive, irrelevant, or differently intended text is processed by this skill unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very common natural-language requests such as '帮我理清思路' and '不知道怎么组织', which can overlap with many unrelated conversations. In an agent environment that auto-selects skills based on broad trigger text, this can cause unintended invocation and unnecessary exposure of user content to the skill's instructions, creating prompt-routing and context-confusion risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation says pasted text alone can trigger the default shortcut flow, which is ambiguous and may cause the skill to activate on arbitrary user-provided content without explicit consent. In multi-skill agents, this increases the chance of accidental routing, overcollection of sensitive text, and interference with a user's intended workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The metadata description embeds many broad natural-language trigger phrases such as '帮我理清思路' and '逻辑有问题', which are common in ordinary conversation and can cause the skill to activate when the user did not explicitly request this specific tool. Unintended activation can misroute user requests, override more appropriate skills, and create prompt-selection ambiguity in multi-skill environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes ambiguous phrases like '帮我理清思路', '帮我重新组织', and '演讲结构/汇报结构', which overlap heavily with routine assistant requests and other writing/planning skills. In a router-driven agent system, such generic triggers increase false activations and may divert user input into this skill without clear consent or task fit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guided-mode activation condition treats statements like '帮我理清思路' or '我想表达XX但不知道怎么组织' as sufficient to enter the skill, but those are common-purpose assistance requests. This broad boundary makes the skill context more dangerous because the skill is public and positioned in a larger ecosystem with adjacent skills, so overlap can cause accidental invocation and incorrect workflow transitions.

Content

No source excerpt is available for this finding.

Ae2

Medium
Category
analysis-evasion
Confidence
90% confidence
Finding

Artifact content does not match its filename extension

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document declares Chinese as the default language via lang="zh", which sets the page's initial locale before any user choice is made. Although a language switcher exists later, the initial forced locale can violate language-choice policy because users are placed into Chinese by default rather than being asked or respecting a neutral default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The page markets numerous operational capabilities such as 7-type diagnosis, MECE enforcement, SCQA auto-selection, and training workflows, but the actual code only implements a static marketing page with language and theme toggles. In an agent-skill ecosystem, overstating implementation can mislead users and upstream agents into relying on controls or processing behaviors that do not exist, creating unsafe trust assumptions and incorrect handling of user data or outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all instructional content in Chinese and does not indicate that the user can choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is reportable unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The technical specs state 'Language | Chinese-first content; works with English input and output.' This expresses a default language/locale preference that may bias behavior toward Chinese even when the user has not opted in, and no explicit language selection mechanism is documented nearby.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The training-mode trigger includes the phrase '练一下', which is highly generic and could match many unrelated user intents. While lower impact than the main routing rules, it still broadens activation surface and can unexpectedly switch the interaction into training mode instead of fulfilling the user's actual request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains instructional content exclusively in Chinese, beginning with the title at L001 and continuing throughout the file. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.