Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - 评估引擎脚本移至 scripts/evaluation-engine.js
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local quality-assessment helper that reads skill files and writes a Markdown report, with no evidence of hidden execution, network access, credential use, or persistence.
Install only if you are comfortable with a Chinese-language quality checker that reads the skill directory you point it at and writes a local Markdown report. Treat its scores as heuristic guidance, not a definitive security or marketplace approval decision, and choose the output path carefully because an existing same-named report could be overwritten.
Referenced artifact was not completely inspected
- 评估引擎脚本移至 scripts/evaluation-engine.js
Referenced artifact was not completely inspected
- 评估引擎脚本移至 scripts/evaluation-engine.js
Referenced artifact was not completely inspected
- 评估引擎脚本移至 scripts/evaluation-engine.js
Referenced artifact was not completely inspected
- 评估引擎脚本移至 scripts/evaluation-engine.js
The manifest description and primary user-facing headings are written entirely in Chinese, and the usage examples also assume Chinese-language interaction. This creates a language/locale constraint without any opt-in, alternative language option, or documentation that the skill is intentionally region-specific.
This markdown template is entirely written in Chinese and provides fixed Chinese section headings and labels, which constrains generated evaluations to a specific language. The file does not offer an opt-in/opt-out mechanism or state that the skill is intentionally region-specific, so it appears to violate the language/locale choice policy.
This markdown reference document is written entirely in Chinese and presents the evaluation standard as the skill's canonical guidance without offering an alternative language, opt-in, or explanation for a locale-specific requirement. Under the policy, forcing a specific language without user choice is a natural-language locale violation.
The manifest promises automated six-dimensional evaluation of skills, suggesting meaningful assessment across technical depth, cognition, orchestration, evolution, market validation, and user experience. However, the C/O/E/M/U evaluators mostly score by checking whether specific words appear in SKILL.md, which materially differs from evaluating actual skill capabilities or evidence for those dimensions.
This .js code contains multiple user-facing console messages in Chinese, including usage instructions, errors, and success output. Because the skill does not offer language selection or explain that it is intentionally region/language-specific, it appears to enforce a specific locale without user opt-in.
The manifest describes an assessment assistant, which primarily implies analyzing skills and producing evaluation results. In this file, the CLI implementation goes beyond in-memory evaluation and persists a Markdown report to a user-specified filesystem location, which is an additional side effect not reflected in the manifest description.
This markdown file presents its title and content in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the natural-language policy rules, forcing a specific language without user opt-in is a policy concern.
No suspicious patterns detected.