Back to skill

Security audit

IM智能提醒

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 study-reminder skill that is purpose-aligned and mostly well-scoped, with consent controls for reminders, sharing, and status sync.

Install this only for a Chinese-language K12 study-reminder context where scheduled reminders and local memory are expected. Users should confirm reminder consent, cross-skill sharing, parent/guardian visibility, quiet hours, and deletion/pause controls before enabling it, especially for minors or non-mainland-China deployments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Manifest 在 L003 宣称“提醒内容本身不在这里生成”,仅负责排期、合并与发送;但正文 L173-L174、L197-L210、L230-L240、L257-L267、L288-L292 明确给出本技能生成具体提醒内容、问题甚至变形题的行为。这构成文档声明与实际职责描述的直接矛盾。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L149 明确写着“本 SKILL 不改写别人的档案”,但 L396-L398 又写明会向学习DNA、每周学习复盘、学习系统协调器回写多种状态摘要。这不是单纯信息不完整,而是文档内部对是否向其他系统写回结果存在直接张力,容易误导开发者对实际副作用的理解。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill file is written as Chinese-only operational guidance, including reminder content examples such as the user-facing prompt on L060. Under the policy rule for language or locale, this can be a violation when a skill constrains language without user opt-in or an explicit justification that it is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill-support document is written in Chinese and contains no indication that language selection is optional or limited to a China-specific deployment. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shared skill guidance uses only Chinese-language instructions and examples throughout, with no indication that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is reportable unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Lines L004-L008 declare this file as the single source of truth for repository-wide terminology, and the required terms are presented exclusively in Chinese. This effectively imposes a language/locale choice across all dependent skills without offering user choice or stating a region-specific justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The schema's natural-language metadata and descriptions are written entirely in Chinese, including the top-level note and description, with no indication that language selection is user-configurable or that the schema is intentionally limited to a Chinese-only deployment. Under the policy rule for language/locale constraints, this can be a natural-language policy concern when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The comment text is written entirely in Chinese and presents the protocol/example context in a fixed language. Under the policy rule for language or locale, this is a natural-language locale choice embedded in the file without any visible opt-in or alternative language indication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.