Back to skill

Security audit

Chinese-Encoding-Handler

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a Chinese encoding helper, but it asks users to make persistent PowerShell changes while the package does not include the scripts it claims to run.

Review this before installing. Verify the actual PowerShell scripts from a trusted source, avoid running -Permanent until you understand exactly what profile or terminal settings it changes, and back up files before using write or batch conversion examples.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
# 涓枃缂栫爜澶勭悊 Skill 淇鎶ュ憡

## 淇姒傝堪

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# 涓枃缂栫爜澶勭悊 Skill 淇鎶ュ憡

## 淇姒傝堪

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · archive/fix-report.md (reported line 1)May include surrounding context.

md
# 涓枃缂栫爜澶勭悊 Skill 淇鎶ュ憡

## 淇姒傝堪

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly advertises a '-Permanent' option for terminal configuration without warning that it may persistently modify a user PowerShell profile or terminal environment. Persistent configuration changes can have longer-lived effects than users expect, and in skill contexts they can alter future shell behavior beyond the immediate task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to run a mode that permanently modifies their PowerShell profile, but the warning about persistence appears much later and is not prominent at the point of use. In an agent skill context, changing shell startup configuration can have lasting side effects beyond the immediate task and may surprise users or automation environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README shows write, append, and in-place conversion workflows that can overwrite existing files, including a batch loop that rewrites files in place, without a nearby warning about backup, data loss, or corruption risk if encoding detection is wrong. In a skill meant to be copied verbatim by users or agents, these examples can lead to unintended modification of real user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language content of the skill is presented only in Chinese, including description, usage, troubleshooting, and examples. This effectively forces a specific language for users without any opt-in or documented justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation instructs users to perform file writes and a permanent terminal fix requiring administrator privileges, but it does not clearly warn about persistence, configuration changes, or possible system/data side effects. In an agent skill context, insufficient safety guidance around state-changing operations can lead users or downstream automation to modify files or terminal settings in ways that are hard to audit or revert.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The document title and surrounding natural-language content are entirely in Chinese, and there is no visible statement offering a language choice or explaining that the skill is region- or locale-specific. Under the language/locale policy, forcing a specific language without opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The report states '中文内容正常显示' as an acceptance criterion, which indicates a language-specific requirement. In this file, there is no accompanying explanation that the skill is region-specific or that users can opt into this locale expectation, so it may conflict with organizational language/locale choice policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The review method explicitly includes '中文验证', and the document is written entirely in Chinese, but the file does not state that Chinese is optional or that the skill is intentionally restricted to a Chinese-only/regional use case. Under the policy, forcing a specific language or locale without opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

Lines L098-L100 state all example scripts are '完整' and '可独立运行', yet the same report identifies scripts/encoding-detector.ps1 as a missing core function (L039, L112, L129, L179) and flags documentation/code inconsistency (L092, L167). Given that the review itself treats the missing detector as core and blocking delivery, the blanket claim that every example is complete and independently runnable contradicts the report's own stated system state.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae2

Medium
Category
analysis-evasion
Confidence
90% confidence
Finding

Artifact content does not match its filename extension

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
98% confidence
Finding

This second finding refers to the same oversized repetitive content on line 1 and is consistent with deliberate or accidental context flooding. In an agent setting, such content can crowd out higher-priority instructions, increase cost/latency, and reduce the reliability of security review or task execution.

Content

Scanner excerpt · test/test-large.txt (reported line 1)May include surrounding context.

text
中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文
...[truncated 28 chars]

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
98% confidence
Finding

This second finding refers to the same oversized repetitive content on line 1 and is consistent with deliberate or accidental context flooding. In an agent setting, such content can crowd out higher-priority instructions, increase cost/latency, and reduce the reliability of security review or task execution.

Content

Scanner excerpt · test/test-large.txt (reported line 1)May include surrounding context.

text
试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行 中文测试行
...[truncated 28 chars]

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural language almost exclusively in Chinese, including headings, results, and the acceptance conclusion. Under the policy rule, forcing a specific language without user opt-in or a clearly documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes a direct example for safe-write.ps1 that writes content to a user-specified path, which can alter existing files. The surrounding documentation does not warn users about possible overwrite or modification effects, so the data-impacting behavior is not clearly disclosed here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Lines L029-L034 list safe-write.ps1 under '通过项' with only positive assessments, but later lines L040, L051, L165, and L188 explicitly state that safe-write.ps1 lacks a -Test parameter/self-check and needs remediation. This is an active contradiction within the document's intent statements about that component's completeness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.