Back to skill

Security audit

微观世界想象器

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese K12 chemistry tutoring skill with consent-gated profile reading and no code execution or profile writing.

Install this for Chinese-language chemistry tutoring in Mainland China-style K12 contexts. For other countries, regions, or languages, localize the crisis contacts, curriculum assumptions, legal consent rules, and user-facing language before exposing it to students. Confirm profile memory consent before using any long-term learning profile data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document is entirely written in Chinese and includes China-specific guidance and phrasing, but it does not state that the skill is limited to Chinese-speaking users or provide any language-choice mechanism. Under the policy rule for natural-language locale constraints, this is a language/locale restriction that is not explicitly justified as an opt-in or region-specific deployment default within the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema contains user- and operator-facing natural-language descriptions entirely in Chinese, including the top-level note and description fields. Under the policy, forcing a specific language without opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document states that the repository is designed for Mainland China Chinese K12 scenarios, with simplified Chinese phrasing and Mainland China safety channels as defaults. This is a natural-language locale restriction that applies globally, but the file does not present it as a user choice or opt-in within the skill behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the natural-language policy check, forcing a specific language without opt-in is a locale-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.