Ae4
- Category
- analysis-evasion
- Confidence
- 80% confidence
- Finding
Suspicious Unicode normalization or mixed-script content
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a Chinese K12 physics tutoring skill with disclosed, consent-gated optional memory, wrong-answer handoff, and reminder behavior.
Before installing, confirm this skill is for Chinese K12 physics tutoring and that the platform enforces the stated consent gates. Leave memory, cross-skill sharing, wrong-answer archival, and reminders off unless the student or guardian explicitly wants those features.
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
The template explicitly says students can say very broad phrases like '这道题不会' and the AI should infer missing slots automatically, which lowers specificity for activation and classification. In a multi-skill environment, broad triggers can cause the physics coach to engage on ambiguous or non-physics requests, increasing unintended handling, privacy spillover into follow-up questioning, and incorrect routing instead of the safer specialized skill.
The quick-mode trigger uses urgency phrases such as '我赶时间/明天就考' to bypass normal intent recognition and jump directly into template ⑤. Because urgency is common across many student conversations, this can trigger the skill without confirming that the request is actually an in-scope physics problem, making accidental activation and misrouting more likely.
This reference file begins with a Chinese-only title and all instructional content is presented exclusively in Chinese. Under the policy, forcing a specific language without offering the user a language or locale choice can be a natural-language policy violation.
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
The file’s instructional content and worked examples are fully presented in Chinese, and there is no natural-language indication that users may choose another language or that Chinese is a justified locale-specific requirement. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.
Suspicious Unicode normalization or mixed-script content
The document begins and continues as Chinese-only instructional content, and there is no natural-language indication that users may choose another language or that the skill is intentionally restricted to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This distributed schema gives the physics problem coach access to a long-term learner profile structure, including consent and archival metadata, even though the skill description says it should operate only in the current session by default unless explicit enablement occurs. In a student-facing educational context, exposing long-term profile fields creates a real risk of over-collection, unauthorized reads/writes, or future prompt/implementation drift causing the skill to persist sensitive data beyond the user's expectation.
The schema description and embedded field values are entirely Chinese-facing, and the enumerated user-facing values throughout the file assume Chinese language use without offering any language choice. For a shared schema distributed across skills, this is a natural-language locale constraint that is not justified here as region-specific or opt-in.
The schema includes learner-profile capabilities unrelated to solving a single physics problem, such as interest tracking, parent-sharing controls, reminder consent, and safety/crisis archival. For a minor-focused tutoring skill, this broadens the accessible data surface substantially and increases the chance that sensitive educational, behavioral, or family-related data is collected, inferred, or retained without a clear necessity tied to the skill's stated function.
The manifest says this skill defaults to working only in the current session and does not schedule reminders unless the student explicitly enables that feature. This distributed schema for the skill includes the reminder_enqueue handover path, meaning the skill is equipped to send reminder requests to another skill, which is broader than the default in-session coaching behavior described in the manifest.
The manifest states the skill does not archive wrong answers by default and that such behavior must be explicitly enabled. This schema copy includes wrong_answer_handover structures and a fixed recipient of xiaozhi-correction-notebook, indicating an implemented cross-skill pathway for wrong-answer archival beyond the default coaching-only scope.
The file is entirely written as normative instructional content in Chinese and includes user-facing phrasing the skill should use, but it does not indicate that Chinese is optional or limited to a China-specific audience. Under the policy rule, forcing a specific language or locale without user opt-in can be a natural-language policy violation.
Suspicious Unicode normalization or mixed-script content
The text states the library is designed for '中国大陆的中文 K12 场景' and sets simplified Chinese, mainland curriculum alignment, and mainland crisis channels as defaults. Although it includes deployment caveats for other regions, it does not offer end users a language/locale choice or opt-in, so this is a natural-language locale policy constraint.
SQP-3 applies to all file types and covers language or locale policy violations. This reference material presents all instructional content in Chinese and does not provide any user opt-in, alternative language option, or justification for a Chinese-only constraint.
This markdown resource presents all instructional content in a single language and does not indicate that Chinese is optional, user-selected, or required by a justified regional scope. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
No suspicious patterns detected.