Back to skill

Security audit

zhang-yiming-perspective

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a Zhang Yiming persona/advice skill, but it quietly performs git-based update checks and can activate on broad phrases, so it should be reviewed before installation.

Install only if you are comfortable with a Chinese-language persona skill that may trigger broadly and use web search for factual questions. Review or remove the silent version-check section if you do not want the agent reading git metadata, contacting the git remote, or writing `.last-update-check` during normal use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation phrases are extremely broad, including generic references like '字节怎么看', '一鸣怎么选择', and even '一鸣', which can cause accidental triggering in unrelated conversations. Because the skill then enforces strong roleplay and hidden workflow behavior, unintended activation can override user intent and indirectly trigger unnecessary tool-use or policy-shaping behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill is written to operate in Chinese and instructs the agent to answer in a specific persona and style, but it does not state that this is a Chinese-only skill or allow the user to choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This persona/advisory skill instructs the agent to inspect local repository state, query the git remote, and write a timestamp file, which exceeds the minimum capability needed for answering perspective questions. That creates unnecessary filesystem and network side effects, and could leak repository metadata or normalize hidden tool use unrelated to the user’s request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Requiring git-based remote version checks for a roleplay/persona skill is unjustified and grants an unnecessary external communication path. Even if the commands are limited, they can reveal repository origin details, create unexpected outbound traffic, and expand the attack surface for a skill whose stated purpose is purely conversational analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains user-facing natural language entirely in Chinese and does not indicate that the skill or document is intentionally limited to Chinese-speaking users or a China-specific context. Under the language/locale policy rule, forcing a single language without opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all substantive instructions and analysis in Chinese, but does not indicate that the skill is China-specific or offer an opt-in or alternative language, which can conflict with a policy requiring user language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents all instructions and reference material in a single language and does not indicate that Chinese is optional or required for a specific regional context. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file is entirely framed in Chinese from the title onward, with no indication that alternative languages are supported or that the language choice is optional. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all substantive instructions and content in Chinese only, with no indication that the user opted into that language and no documented region-specific requirement justifying the constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.