Back to skill

Security audit

思维梯度训练师

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese K12 math practice skill that stores limited learning progress and can queue consented reminders, with no evidence of hidden code or data exfiltration.

This skill is reasonable to install for Chinese-language middle/high-school math practice. Before using it with minors or outside Mainland China, confirm local consent rules, emergency-contact localization, and whether profile sharing and reminders are enabled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description at L003 states '本 SKILL 不自己提醒', implying the skill should not perform reminder behavior on its own. However, Module D explicitly says that upon student consent it will generate a reminder_enqueue request for weekly growth checks, which is operational reminder behavior initiated by this skill even if delivery is delegated to another skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and all instructional content are written in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-language or China-specific educational context. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire file is written in Chinese and presents the resource as the reference material for the skill, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file presents all operational safety instructions exclusively in Chinese, and it does not indicate that users or deployers can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The shared hint-ladder allows escalation to L5/L6, including a full walkthrough of the original problem, while this skill is explicitly a gradient trainer whose own shared table caps it at L4 and says to step back down when the layer is too hard. That mismatch can cause the agent to drift into prohibited in-the-moment problem solving, weakening intended guardrails around practice-only behavior and potentially violating the skill’s routing boundary to the dedicated problem-solving coach.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file hard-codes the skill library for Mainland China Chinese K12 use and says deployments to other regions should not be used until localization work is done. In an education product used by minors, this can cause unsafe or inappropriate crisis contacts, legal-consent assumptions, and curriculum guidance if the user is outside the intended region, especially when no user choice or runtime locale confirmation is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is written entirely in Chinese and establishes repository-wide terminology and normative wording, but it does not indicate that language choice is optional or limited to a Chinese-only deployment context. Because the policy category applies to natural-language content in any file type, this is a locale/language constraint that appears to be imposed without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.