Back to skill

Security audit

智能错题本

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 wrong-answer notebook skill that uses disclosed student learning records, cross-skill handoffs, and reminders in ways that fit its stated purpose.

Before installing, confirm you want a Chinese K12 learning-record skill that can keep wrong-answer history, share minimal data with related learning skills, enqueue reminders, and update a learning profile when the relevant consent settings are enabled. Use the pause, delete, export, and sharing controls if the student or guardian does not want long-term memory, parent visibility, or cross-skill sharing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description states activation requires '有一道具体做错的题' and says generic requests without a problem should first ask for the problem and not register or analyze it. However, the file also documents direct handling of requests like '我的错题本里有什么', '帮我整理本章错题', and '帮我生成学期错题报告', which operate over stored history rather than a currently supplied wrong problem.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is entirely written as Chinese-only trigger phrases and operating guidance, implying the skill is intended to activate and operate in Chinese. The file does not offer user opt-in for language/locale selection or explain that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written as mandatory operational guidance in Chinese, including required field values and handoff instructions, but it does not state that the skill is China/Chinese-only or offer any language opt-in. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is written entirely in Chinese and presents normative skill parameters and instructions without any indication that language is selectable or limited to a China-specific deployment. This can violate language/locale policy when a skill implicitly forces a specific language or locale without user opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire shared guidance file is written in Chinese and presents mandatory behavioral instructions for skills, but it does not indicate that Chinese is optional, user-selected, or limited to a China-specific deployment. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description explicitly includes '出一道同类题' as an activation example. But the '不触发' table includes '请求同类练习 | 帮我出几道这类型的题练练', which is an active contradiction in the skill's own documentation about when it should handle a request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The JSON comment on L02 is written entirely in Chinese and provides protocol guidance without any indication that language selection is optional or tied to a documented regional requirement. This can reflect a language/locale policy issue because the skill artifact appears to assume a fixed language rather than offering user opt-in or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

L11 明确规定内容、话术和安全求助渠道默认面向中国大陆中文场景,这属于自然语言层面的语言/locale 限制。虽然后文说明了其他地区部署前需做本地化处理,但这里仍是默认强制约束,而不是向用户提供语言或地区选择。

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON manifest/example includes a trigger-like field, "handoverTrigger": "stubborn_weakness", but does not define what conditions qualify for that trigger or when it should not be used. In a manifest/example file, that lack of specificity can lead to inconsistent or overly broad activation of the wrong-answer handover flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.