Back to skill

Security audit

生物概念网络构建器

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language biology study skill with consent-gated profile and reminder handoffs, and no evidence of hidden execution, exfiltration, or unsafe persistence.

Install this only in a Chinese K12 learning context where persistent learning profiles and reminder queues are acceptable. Before enabling memory or cross-skill sharing, verify that the student or guardian understands what biology concept data may be saved, shared, corrected, exported, or deleted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The schema’s natural-language metadata and enumerated human-facing values are written exclusively in Chinese, including the main note and description. Because the file provides no indication that Chinese is an optional or region-specific locale choice, it appears to enforce a single language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes this skill as helping students organize biology concepts and distinguish relationships among concepts. This distributed schema explicitly scopes the skill to three handover paths, including subject profile writeback and reminder enqueue, which are data-sharing and reminder-scheduling capabilities not described as part of the skill’s user-facing purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description is written entirely in Chinese and presents protocol guidance as mandatory text, but the file does not indicate that this schema is limited to a Chinese-language or region-specific deployment. Under the policy, forcing a specific language without user choice or explicit justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s stated purpose is to connect biology concepts and build chapter-level knowledge structures. Including the reminder_enqueue handover path and a full reminder payload schema adds a notification/reminder capability that is not an obvious requirement for concept mapping or concept clarification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest frames the skill as an instructional organizer for biology concepts, not as a component that updates persistent learner profiles. The subject_profile_writeback path and profileData structure permit modifying subjectExtensions.biology data, which is a separate capability from explaining or structuring concepts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This top-level description mandates protocol semantics in Chinese only, with no indication that users or integrators may choose another language and no explicit locale restriction. Because the requirement applies across the schema, it constitutes a language/locale policy issue rather than a mere translation preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document presents all instructional content in Chinese and does not indicate that users can choose another language. Under the natural-language policy check, forcing a specific language without user opt-in can be a policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

L11 明确说明本库按“中国大陆的中文 K12 场景”设计,并将示例话术与求助渠道默认设为中国大陆。这属于自然语言层面的语言/地区约束;虽然后文提供了跨地区部署注意事项,但默认策略仍强制特定语言与地区,未体现终端用户选择或显式 opt-in。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.