Back to skill

Security audit

康奈尔笔记

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 Cornell-notes skill whose note storage, cross-skill summaries, and reminder handoff are disclosed and scoped to its study-notes purpose.

Install this only for its intended Chinese K12 study-notes context. Before enabling long-term profiles or reminders, confirm profile, cross-skill sharing, parent/guardian, and reminder consent settings are configured; review the self-test reminder template so it cannot override the main session-only recall-status rule.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description includes broad trigger phrases such as '提炼今天学的内容' and '康奈尔笔记怎么做', which can plausibly match ordinary study conversation outside a clear note-organizing intent. This can cause unintended activation, leading to unnecessary access to note content, profile state, or cross-skill workflows when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructions, examples, and operational guidance only in Chinese, and it does not indicate that the user can select another language or that the skill is intentionally restricted to a Chinese-speaking audience. That can violate language/locale policy when a skill effectively forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide introduces a structured self-test training record format and an IM reminder field that imply storing recall-performance data beyond the current conversation. This conflicts with the stated skill scope that self-test recall status is only used in-session and that reminders require explicit user consent, creating a real risk of over-collection and retention of student learning data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The policy requires flagging natural-language cases that force a specific language or locale without user opt-in. This protocol is entirely Chinese-language and does not indicate that Chinese is optional, user-selected, or required for a documented region-specific deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L11 明确说明本库按“中国大陆的中文 K12 场景”设计,示例与话术为简体中文,安全求助渠道默认中国大陆。这属于自然语言层面的语言/地域默认约束;虽然 L13-L17 提到跨地区部署前需本地化,但未体现运行时的用户选择或明确 opt-in。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document defines the repository-wide vocabulary entirely in Chinese and states it is the only allowed source for terminology and enums. This imposes a specific language standard without any opt-in, alternative locale, or justification that the skill is region-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The line '需要IM提醒的' operationalizes reminders without embedding the manifest's required consent condition. In a student-facing skill, this can normalize sending or tracking reminders absent explicit approval, leading to unauthorized outreach or expectation mismatches around messaging behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.