Back to skill

Security audit

30天学习计划制定师

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese K12 study-planning skill with consent-gated profile use, reminder handoff, and plan storage controls, and I found no hidden code execution or deceptive behavior.

Install this only in a Chinese K12 learning context unless the operator localizes language, curriculum assumptions, consent rules, and crisis-help channels. Before use, confirm the student or guardian understands that profile summaries, parent dashboards, plan storage, and reminders are optional and should stay off unless explicitly enabled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description says the skill can activate on phrases like "帮我制定学习计划" and especially "我不知道怎么安排时间", which are common, broad utterances that could arise in many contexts beyond this specific 30-day study-planning skill. The file does not provide negative examples or tighter scope constraints for when these phrases should not invoke the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description, prompts, trigger phrases, and user-facing outputs are entirely in Chinese, and the file does not indicate that the user can choose another language or that the skill is intentionally restricted to a Chinese-language region. Under the policy, a fixed language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest promises a narrow, consent-gated read of a limited profile summary, but the spec expands behavior to 'historical dialogue data' and analysis of learning rhythm/preferences. This broader language weakens data-minimization boundaries and can lead an implementation to access more historical or behavioral data than the user was told would be used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says reminder sending is delegated to another skill and disabled by default unless the student explicitly consents, but this section defines exam-day reminder content and timing behavior inside this skill. That creates scope drift: an orchestrator or downstream agent could reasonably treat this skill as authorized to schedule or compose reminders without a separate, current consent check.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This section authorizes writing generated plans back into a shared learning profile, while the manifest only declares three default-off actions and does not disclose profile writeback as a separate sensitive operation. Even though the text adds conditions, the mismatch can bypass user expectations and cause persistent cross-skill data sharing beyond what was transparently declared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This shared skill guidance is written entirely in Chinese and includes normative behavioral instructions for skills, but it does not indicate that language choice should follow the user's preference or that the policy is limited to a Chinese-only deployment. Under the policy rule, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L11 明确规定“本库按中国大陆的中文 K12 场景设计”,并将示例话术和求助渠道默认绑定到简体中文与中国大陆。这构成了显式的语言/地区默认策略;虽然后文说明跨地区部署前需调整,但没有提供面向用户的语言或地区选择/确认机制。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This manifest/schema file embeds user- and developer-facing natural-language descriptions entirely in Chinese, including the main title/description and operational notes. That can constitute a language policy violation when the skill forces a specific language without user opt-in or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.