Back to skill

Security audit

物理实验思维教练

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese K12 physics-lab coaching skill with proportionate memory, reminder, safety, and handoff rules, and I found no hidden code, exfiltration, or deceptive behavior.

Install this only for users who are comfortable with a Simplified Chinese, Mainland China K12 tutoring context. Before using profile memory, parent summaries, cross-skill sharing, or reminders, confirm the platform consent settings match the student and guardian expectations; localize crisis contacts if used outside Mainland China.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and trigger examples are entirely in Chinese, presenting the skill as operating in a single language without offering a user language choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown skill reference uses Chinese as the sole instructional language from the title onward, and there is no visible opt-in or alternative language guidance. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, beginning with the title and audience description, but it does not indicate that the language is optional or limited to a Chinese-speaking context by policy. Under the language/locale policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains natural-language instructional content exclusively in Chinese, and there is no indication that the user can opt into another language or that the skill is intentionally limited to Chinese-speaking users. Under the language/locale policy rule, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's operational instructions and user-facing example language are fully Chinese, and there is no indication that users can opt into another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless a locale-specific constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that the repository is designed for Mainland China Chinese K12 scenarios, with Simplified Chinese phrasing and Mainland China safety channels as defaults. This is a locale/language constraint expressed as a default policy, but it does not provide user choice or opt-in at the point of use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes invocation-style behavior guidance for reminder creation, but it does not specify what user requests should or should not cause a reminder_enqueue handoff. Without explicit trigger phrases, exclusions, or scope limits, reminder-related skills may interpret a broad range of ordinary planning language as sufficient to enqueue reminders.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file defines the shared vocabulary entirely in Chinese and states it is the sole source of terminology and enums for all skills. Because this requirement is framed as a global contract rather than a region-specific constraint or an optional locale choice, it can constitute a language-policy violation under the locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire reference file is written only in Chinese and does not indicate any option for alternative languages or user language preference. Under the policy criteria, a skill that effectively forces a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.