Back to skill

Security audit

转行创业顾问

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese career, skill-learning, and small-business exploration guide with risk guardrails, and I found no hidden execution, persistence, credential use, or exfiltration behavior.

Install only if you want a Chinese-language advisor for career, skill-learning, freelancing, and small-business exploration. Treat the investing content as educational only: do not rely on it for personal buy/sell decisions, and require region-specific regulatory or professional confirmation before acting with real money, licenses, contracts, health/safety risks, or significant spending.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
This file is a full personal stock investing/trading guidance module embedded in a skill whose stated purpose is industry and career-path exploration. That scope mismatch is dangerous because it can cause the agent to route users seeking career advice into regulated, high-risk financial guidance workflows, increasing the chance of inappropriate financial instruction and policy boundary violations.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
The document contains detailed operational instruction on stock trading, account opening, market access, order placement, chart analysis, and practice workflows that are not justified by the parent skill's career-path mission. In context, this broadens the agent into giving actionable securities education where users may reasonably act on it, creating elevated legal, safety, and trust risks even though the text includes some disclaimers.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The skill declares a very broad activation scope across industry research, job transition, skill learning, freelancing, store-opening, and startup validation. Overbroad scope can cause the agent to activate on loosely related prompts and deliver high-authority guidance in domains with materially different risks, increasing the chance of inappropriate advice, unintended data collection, or bypass of more specialized safeguards.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The instruction to default broad requests into a 'quick judgment' path without strong gating is ambiguous and may over-trigger the skill for generic exploratory questions. In practice, that can make the agent infer user intent too aggressively, producing structured recommendations or experiments where a narrower, safer response or clarification should have been used.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to assume a default locale and other user attributes (e.g. '中国大陆、零基础、每周 8 小时') if the user does not answer clarifying questions. This can cause the system to generate advice based on an unverified jurisdiction or market, which is risky when recommendations depend on local regulation, labor markets, or platform availability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition is broad enough to activate on many generic beginner requests such as 'teach me' or 'how do I start,' which can cause the skill to run outside its intended scope. In this skill, over-invocation is risky because it may force a heavy, domain-specific workflow, encourage unnecessary web lookups or procurement guidance, and reduce the reliability of routing and safety checks for unrelated user intents.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The guidance explicitly applies a default version for '中国大陆、零基础、低预算' when key user information is missing, which can steer users into advice based on an assumed jurisdiction and constraints they did not confirm. In a career-transition and entrepreneurship skill, legal requirements, market conditions, licensing, and resource assumptions vary significantly by region, so an unconsented locale default can produce materially misleading or unsafe recommendations.

Static analysis

No suspicious patterns detected.