Back to skill

Security audit

物理错误DNA

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese K12 physics learning-profile skill that stores and shares only scoped learning-error data when the relevant user consents are enabled.

Before installing, confirm this will be used in the intended Mainland China Chinese K12 context, and review the consent settings for student profiles, cross-skill sharing, reminders, parent-visible summaries, and deletion/export rights. Outside that context, localize curriculum assumptions and crisis-contact guidance first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and the full document are written in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language or China-specific context. Under the policy, forcing a specific language without user opt-in is a reportable locale-policy issue.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema includes hard-coded Chinese-only enum values such as consent subjects, along with Chinese-only descriptions and examples throughout the file. Because the skill does not indicate that it is intentionally limited to a Chinese locale or provide any user opt-in or alternative locale handling, this creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is entirely written in Chinese and provides operational skill guidance without indicating that users may choose another language or that the skill is limited to a Chinese-speaking or China-specific deployment. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This schema embeds natural-language instructions and enumerated value labels in Chinese, such as the note on skill scope and later user-facing status/dimension labels, but does not indicate that the protocol is intentionally China/Chinese-only or provide any language/locale opt-in. That can violate the policy against forcing a specific language without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema requires Chinese-only enum values for basicDimension, and similar Chinese-only status values appear elsewhere. Because these values may propagate across skills and user-facing outputs, the file effectively enforces a specific language without documenting a justified regional constraint or offering alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The status enum uses Chinese-only values, which can impose a fixed locale on downstream systems and outputs. The file does not state that this is a region-specific compliance requirement or otherwise justify the language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document states that the repository is designed for ‘中国大陆的中文 K12 场景’, with simplified Chinese wording and mainland-China crisis channels as defaults. This is a natural-language locale constraint, and while it notes operators must localize before deployment elsewhere, it does not offer end users a language/locale choice or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown lists invocation phrases such as “查看我的[档案/记录]”, “更正我的[档案]”, and “删除我的[档案]” as control entrances, but it does not define where these phrases apply, how exact they must be, or examples of similar phrases that should not trigger the skill behavior. Because these are natural-language triggers in documentation, the lack of specificity could lead to unintended invocation in ordinary conversation about records or deletion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and introductory description are entirely in Chinese, and the file does not indicate that language selection is optional or that the resource is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents all instructional content exclusively in Chinese and does not mention any language choice, opt-in, or region-specific justification. Under the policy rule for natural-language constraints, this can be treated as a locale/language restriction that is not documented as optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.