Back to skill

Security audit

家语

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language family memory assistant that stores sensitive family records locally and may use configured messaging integrations, with no evidence of hidden code, exfiltration, or destructive behavior.

Install only if you are comfortable keeping family records in the workspace. Before use, agree on who may contribute and read records, avoid storing unnecessary identifiers or child details, review any WeCom or Tencent Docs destinations, and keep the workspace protected because the artifact does not define encryption or retention controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/agents.md:77
Finding

Unprotected Plaintext Storage of Sensitive Family Records

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to use specific Chinese honorifics ("您"、"请") enforces a language/locale behavior in the skill's natural-language policy. The file does not indicate that users can choose another language or that this constraint is limited to a justified region-specific deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The changelog text is entirely in Chinese and presents the skill metadata in a single fixed language. In a general manifest file, this can indicate a language-policy issue because there is no user opt-in, alternative locale, or documented justification that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to continuously collect intimate family data, including messages, media, emotions, activities, and longitudinal history, without any visible privacy notice, consent flow, or data-handling safeguards. In a family context that includes children and elders, silent collection creates a significant risk of oversharing, non-consensual profiling, and accidental exposure of highly sensitive personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented storage model preserves detailed family timelines, growth records, elder histories, decisions, birthdays, roles, and identifiers in persistent files, yet it provides no warning about sensitivity, retention, access control, or breach consequences. This is dangerous because the data set enables deep profiling of household routines, relationships, children, and life events, which could cause severe privacy harm if misused or exposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest names the skill family-meeting-assistant and describes meeting assistance, but this file documents a much broader system: daily memory capture, long-term growth archives, elder oral-history interviews, annual chronicles, and family culture analysis. This is a semantic mismatch between the claimed skill scope and the actual documented operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document instructs the assistant to use Chinese honorific forms such as "您" and "请", which imposes a specific language/register choice. There is no indication that users can opt into another language or communication style, so this creates a natural-language policy concern under the locale/language rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The entire skill specification, examples, file names, prompts, and timezone are fixed to a Chinese-language and China-locale context, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language or locale without opt-in can be a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The cron payload explicitly says to send daily prompts to a family group, and the dependencies include wecom-weisheng-scrm for message pushing. For a skill framed as a family meeting assistant, always-on outbound messaging and social CRM integration go beyond core meeting facilitation unless the manifest explicitly declares that notification/messaging scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language identity metadata presents the skill name and description entirely in Chinese, which may imply a fixed language/locale without offering the user a choice. Under the policy, forced language selection can be a violation unless the locale constraint is documented or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.