Back to skill

Security audit

阅读理解拆解师

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese reading tutor skill with disclosed, consent-gated profile and reminder integrations and no deceptive or executable behavior found.

Install this if you want a Simplified Chinese, mainland China K12 reading-comprehension coach. Before enabling long-term memory, cross-skill sharing, parent sharing, or reminders, review the consent settings and localize the curriculum, privacy, and crisis-help defaults if the learner is outside mainland China.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains a natural-language instruction that stage/grade determination must use the student's self-reported grade and even specifies the exact Chinese prompt "你现在读几年级". That enforces a specific language/locale interaction pattern without offering user choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file title and the entire skill content are presented as a Chinese-only student resource for reading instruction, with no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that users may choose another language or that the skill is limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The schema is explicitly distributed to a Chinese-reading skill and all user-facing descriptions in the file are written only in Chinese, indicating a fixed language context. For a file type covered by policy review, this is a natural-language locale constraint without any opt-in or justification that it is a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema explicitly distributes cross-skill handover capabilities for learner-profile writeback and reminder enqueue to a skill described as reading-comprehension coaching. Even with consent fields present, this expands the skill's effective authority beyond its user-facing purpose, creating a capability/expectation mismatch that can enable unnecessary data sharing or side effects if the skill is invoked in ordinary tutoring flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schema allows this skill to initiate reminder scheduling via handover to an IM reminder system, despite the manifest describing a tutoring-oriented reading assistant rather than a scheduling agent. That mismatch increases privacy and surprise risk because a user seeking reading help may not expect downstream reminder creation, and a compromised or overreaching skill could use this path to generate unsolicited notifications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The schema permits subject_profile_writeback to another system, allowing the skill to modify learner profile data beyond the immediate tutoring interaction. In an educational context this may be product-motivated, but without clear disclosure and strict minimization it creates integrity and privacy risk by letting a narrow-purpose reading skill persist assessments or inferences about the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file's instructional content is entirely in Chinese, including core operating rules and user-facing phrasing, with no indication that users or maintainers may choose another language. Per the policy category, forcing a specific language without opt-in is a natural-language locale violation unless the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The text says the repository is designed for '中国大陆的中文 K12 场景' and defaults safety help channels, curriculum alignment, and legal assumptions to mainland China. This imposes a specific language/locale baseline and regional defaults, which can violate locale-choice policy when applied outside that context without explicit user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file states that other skills '需要提醒时' should generate a reminder_enqueue handoff, but it does not define what conditions qualify as 'need a reminder' or provide exclusions. In a shared convention document, this broad phrasing could lead to inconsistent or unintended reminder invocations across skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document defines the shared vocabulary and instructions entirely in Chinese and states this file is the sole source for terminology across the repository. Because it imposes a single language for repository-wide terminology without any opt-in or documented locale justification, it creates a natural-language locale policy concern under the language-choice rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file imposes a single language/locale for the skill content, which can violate language-choice policy when no user opt-in or documented locale restriction is provided. The opening scope lines establish usage context but do not state that Chinese is optional or limited to a China-specific audience by policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.