Back to skill

Security audit

ai-learning-journal AI学习助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local AI learning journal that writes Markdown notes and summaries, with no executable code or network behavior, but users should know it may activate on casual AI-related comments.

Install only if you want a local, file-backed AI learning journal. Be aware that AI-related remarks may be organized into records under the skill's records directory; ask the agent not to save when you only want a transient conversation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly states it should trigger on very broad AI-related topics, including casual remarks like 'tried Claude today' or 'learned a new prompting trick.' That can cause unintended invocation and unexpected handling of user content, especially because the skill also persists records to disk, increasing privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create and modify persistent Markdown files under a local records directory, but it does not require explicit disclosure or user consent before storing data. Users may casually mention experiences without realizing those details will be written to disk, creating privacy and surprise-retention risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger examples for 'learning guidance' include generic phrases like '这个怎么用比较好?' and '有什么最佳实践吗?', which are common across many unrelated contexts. This ambiguity can cause the skill to activate outside its intended scope and steer conversations into file-backed journaling or AI-learning guidance when the user did not ask for that.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions and invocation examples are presented only in Chinese, and the document does not indicate that users may choose another language. This can violate a language-choice policy when a skill implicitly requires a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger phrases are broad, natural-language requests such as reviewing learning records or asking for a study plan. In a shared assistant environment, these phrases can unintentionally activate the skill during ordinary conversation, causing unexpected behavior such as modifying or surfacing journal content without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README content is entirely in Chinese and does not indicate that the skill is region-specific or that users can opt into another language. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.