Back to skill

Security audit

英语写作进化教练

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese K12 English-writing coaching skill with consent-gated profile features and no executable code or hidden high-risk behavior.

This is suitable for Chinese-speaking K12 English writing practice. Before installing outside mainland China or for non-Chinese users, localize curriculum assumptions, minor-consent rules, and crisis-support contacts. Users should understand that progress/profile data may be saved or shared across related skills only after consent, and they can pause, delete, export, or restrict sharing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description defines the skill entirely in Chinese and presents trigger phrases only in Chinese, which can force a language/locale expectation on users. The file does not indicate that users may interact in another language or choose their preferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and introductory lines are entirely in Chinese and present the file as the reference resource for the skill, with no indication that users can opt into another language. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern unless clearly documented as a justified locale-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The protocol is written entirely in Chinese and includes user-facing phrasing and instructions without indicating that the skill supports other languages or that Chinese is an explicit, justified deployment constraint. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill resource is written as Chinese-only instructional content, including normative guidance for how the skill should classify and explain errors. There is no indication that users may choose another language or locale, so the skill appears to impose a specific language setting rather than offering an opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

文件明确规定示例与话术为简体中文、安全求助渠道默认中国大陆,并要求其他语言或地区部署前先做本地化处理。这属于自然语言层面的语言/地域策略约束;虽然文中说明了跨地区部署需调整,但没有提供面向最终用户的语言/地区选择机制或明确的用户 opt-in。

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

该 markdown 文件声明“本库按中国大陆的中文 K12 场景设计”,但未进一步说明哪些具体技能、哪些使用情境或哪些用户类型不应匹配,属于范围描述较笼统的自然语言约束。对于清单/说明类文件,这种宽泛表述可能让调用方难以判断何时应应用这些约定、何时应排除。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.