Back to skill

Security audit

数学错误DNA

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 math error-analysis skill with persistent learner-profile behavior, but its data use, consent checks, sharing limits, and crisis handling are disclosed and aligned with its educational purpose.

Install this only for the intended Chinese K12 tutoring context or after localizing language, curriculum, consent rules, and crisis-contact guidance. Because it works with student learning records and anxiety signals, verify that profile storage, parent sharing, cross-skill sharing, and reminders are disabled by default unless the user or guardian has consented.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is authored entirely in Chinese and defines user-facing flows, triggers, and outputs only in Chinese, without any mechanism to detect or honor the user's preferred language. This can cause users to misunderstand consent, privacy controls, crisis handling, or data-sharing choices, which is especially risky in a skill that processes student records and anxiety-related signals.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger examples include broad, everyday phrases such as '我数学太差了' that can be said in many contexts, including emotional venting rather than an intentional request to invoke this skill. That increases the risk of unintended activation, unnecessary processing of sensitive educational/anxiety-related data, and accidental cross-skill handoffs in a system that stores learner profiles.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is entirely written in Chinese and is explicitly scoped to a Chinese middle-school context, but it does not state that language use is optional or provide any language-choice guidance. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

该文件标题与全文说明均仅以中文呈现,未见任何关于可选择其他语言或面向特定中文场景的说明。根据规则,若技能内容强制单一语言而没有用户选择或明确的合理限定,属于自然语言层面的政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill file is written in Chinese and defines defaults for Chinese school grade bands, curricula, and policies without any indication that the skill offers a language choice or that it is explicitly limited to a China-specific audience. Under the policy, locale-specific constraints should either be optional for the user or clearly documented as justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The text states the repository is designed for Mainland China Chinese K12 scenarios, with simplified Chinese wording and Mainland China safety/help channels as defaults. Although it includes adaptation steps for other regions, it still sets a fixed language/locale default rather than offering user choice or explicit opt-in, which matches the policy category for locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.