Back to skill

Security audit

Knowledge Base Editor 知识库编辑器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese knowledge-base writing workflow with scoped document creation and review behavior, and I found no hidden execution, exfiltration, or persistence mechanism.

Install this if you want an assistant to help create and maintain Chinese knowledge-base documents. Expect it to read and update project-specific writing records and, with your authorization, write to Feishu or local documents; specify another language or tighter document scope if needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata and default prompt hard-code Chinese-language behavior ('中文知识库', '知识库总编') without indicating that the assistant should adapt to the user's language preference. This can override user expectations, reduce usability, and in some systems may cause instruction-priority conflicts where the skill response language diverges from the user's explicit request.

Static analysis

No suspicious patterns detected.