Back to skill

Security audit

兴趣成长探索计划

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, consent-based interest-tracking guide for students, with clear limits on what it records and shares.

Install for Chinese-language K12 contexts where the operator can honor the stated consent, guardian, deletion, reminder, and localization requirements. Treat the long-term interest record as student data: enable tracking, parent sharing, cross-skill sharing, and reminders only when the student and required guardian understand and agree.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description is written as direct operational guidance entirely in Chinese and the file provides trigger phrases and required user-facing disclosures only in Chinese. There is no indication that the skill is region-specific or that users may choose another language, which creates a natural-language locale policy concern under the rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The protocol text, instructions, and examples are written only in Chinese, which effectively forces a specific language for anyone consuming this shared safety guidance. The file does not state that it is limited to a Chinese-speaking deployment or offer an alternative language/locale option, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language descriptions and policy notes in this schema are entirely in Chinese, including consent-related field descriptions that downstream users or operators may need to understand. For SQP-3, this can be a language/locale policy issue because the file does not offer any language choice or state that the schema is intentionally limited to a Chinese-language or region-specific deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema contains user-facing and operational natural-language descriptions entirely in Chinese, including the top-level scope note and description. Under the policy, forcing a specific language without opt-in or an explicit documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire shared instruction file is written as mandatory operational guidance in Chinese and includes prescribed user-facing wording such as asking and explaining in Chinese. There is no indication that users may choose another language or that the Chinese-only constraint is limited to a documented region-specific context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L11 明确规定“本库按中国大陆的中文 K12 场景设计”,并默认使用简体中文与中国大陆安全求助渠道。这属于语言/地域约束的自然语言策略声明,文件中虽说明跨地区部署需额外处理,但未体现面向终端用户的语言或地区选择/确认机制。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.