Back to skill

Security audit

初高衔接规划师

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese Mainland K12 study-planning skill with disclosed, consent-gated use of learning profile fields and reminder handoff, not hidden or destructive behavior.

Install this only for Chinese-language Mainland China K12 study-planning use, or localize the curriculum, emergency resources, and minor-consent defaults first. Users should pay attention to the profile and reminder consent gates and use the provided controls to view, pause, delete, export, or limit sharing of learning-plan data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document is written entirely in Chinese and contains China-specific operational guidance, including region-specific emergency numbers and instructions such as confirming whether the user is in mainland China before providing them. There is no stated user language choice or explicit opt-in for Chinese-only handling, so this creates a locale/language policy concern for a shared cross-skill safety protocol.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The schema description and enumerated values throughout the file are exclusively in Chinese, and line L015 describes the profile structure only in that locale with no indication that users can choose another language. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire shared skill file is written only in Chinese and includes no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON schema includes natural-language descriptions entirely in Chinese, including the top-level note and description, and does not indicate that language is configurable or limited to a China-specific deployment. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire shared guidance file is written in Chinese and includes user-facing prescribed wording such as the one-sentence explanation to give students during exams. There is no indication that the skill should adapt to the user's preferred language or obtain language opt-in, which can violate a language/locale policy if skills are expected to support user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document states the library is designed for '中国大陆的中文 K12 场景' and fixes examples, wording, and default safety-help channels to Simplified Chinese and Mainland China. This is a natural-language locale policy constraint, and the file does not offer a user choice or opt-in at the point where the constraint is declared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is entirely written in Chinese and presents the skill resource as the reference content for xiaozhi-bridge-planner, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.