Back to skill

Security audit

物理建模教练

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 physics-modeling coaching skill with disclosed profile-memory and reminder handoff behavior, and I did not find hidden execution, exfiltration, or deceptive instructions.

Install this only for a Chinese/Mainland-China K12 physics tutoring context, or localize the curriculum, language, emergency contacts, and minor-consent rules first. Before use, confirm whether profile memory, cross-skill sharing, parent sharing, and reminders are enabled; the skill is benign, but it can handle education records about minors when those permissions are granted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The introduction explicitly promises that out-of-scope content will be confined to the final section and not used for explanation or problem setting, but the rest of the document contradicts that promise. This mismatch is risky because downstream agents and reviewers may rely on the introductory constraint as a safety contract, while the embedded content silently weakens it and can trigger unauthorized advanced instruction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file claims to restrict main content to junior-high scope, yet the main body includes operational high-school formulas and methods such as quantitative mechanical-energy equations. In an educational coaching skill, this is dangerous because it can cause policy/routing failure: the agent may provide out-of-scope instruction despite explicit guardrails, undermining trusted scope boundaries and leading to systematically incorrect or noncompliant behavior.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown resource forces a specific language/locale for all users through its headings and instructional content. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document title and all instructional content are written exclusively in Chinese, and there is no indication that the user can opt into another language or that the skill is intentionally limited to Chinese-language use. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This schema constrains consent-related fields to Chinese-only enum values such as "学生本人" and "监护人", and many descriptive/value fields throughout the file are likewise Chinese-specific. Because SQP-3 applies to all file types, this is a natural-language locale policy concern when the file does not state that the skill is China/Chinese-only or that users can opt into this locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema explicitly distributes handover capabilities including reminder_enqueue to a skill whose manifest says it does not handle reminder/counting workflows. This creates unnecessary authority and broadens the skill's operational scope, increasing the chance of unauthorized cross-skill actions or privacy-impacting reminder creation if the agent is induced to use the available channel.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The schema exposes a fully structured reminder-scheduling payload, including timing, content, priority, and mergeability, which grants the skill a concrete capability unrelated to physics model-selection coaching. Even with consent fields present, giving an unnecessary capability violates least privilege and can enable overreach, user annoyance, or misuse of cross-skill data flows through prompt manipulation or implementation mistakes.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states the repository is designed for simplified Chinese Mainland K12 scenarios and that safety help channels default to Mainland China. This is a locale-specific policy applied by default rather than offered as a user choice, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file discusses 'automatic trigger' phrasing but does not specify precise activation conditions, trigger boundaries, or negative examples for when such wording should or should not be used. Because phrases like '按需提示' and '建议触发' are broad, different skill authors could interpret them inconsistently and create overly broad invocation behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file defines a repository-wide single source of truth entirely in Chinese and mandates that all SKILL.md, references, and schemas must use these definitions. This is a natural-language locale constraint applied globally, but the file does not offer a language choice or explain a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill reference file is written in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown resource presents all instructions and educational content exclusively in Chinese, which can constitute a language/locale policy issue when no user opt-in or alternative language path is provided. The file does not indicate that the skill is intentionally limited to a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON schema contains user- and developer-facing natural-language descriptions exclusively in Chinese, including scope notes and field descriptions, with no indication that the skill is region-specific or that another language is supported. Under the policy rule, forcing a specific language without opt-in can be a locale-policy violation when no justification or choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.