Back to skill

Security audit

学习系统协调器

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese K-12 learning coordinator that routes learning requests and summarizes authorized data; I found no executable, hidden, or deceptive behavior.

Install this only for the intended Chinese K-12 learning workflow. Users should review and configure cross-skill sharing, profile, teacher writeback, parent sharing, and reminder permissions before use; deployments outside mainland China should localize curriculum assumptions, consent rules, and crisis-support contacts first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest explicitly says the skill does not send reminders and does not write back broadly, limiting itself to routing, deduplication, and summary with minimal necessary data. However, the documentation assigns this skill the ability to generate reminder_enqueue, and later describes cross-skill data handoff and writeback validation workflows, which expands behavior beyond the narrow manifest description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This line states that the coordinator '只定义协议、校验格式、按路由表分发,自己不发写回、不存档案', which presents the skill as not originating handoff actions. But line 67 and lines 309-317 explicitly authorize the coordinator to generate reminder_enqueue, so the documentation contradicts itself about whether the skill sends protocol messages.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The opening documentation explicitly states the coordinator does only one thing: decide which skill should receive a request, while retrieval, reminder enqueueing, and writes are done by routed skills. Later passages assign the coordinator behaviors such as reminder initiation/queue generation and three-dimensional weekly aggregation, which contradicts the earlier strict limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest limits this skill to routing, deduplication, and minimal-field aggregation, and explicitly says it does not send reminders. In this example, the coordinator asks whether to remind the student and then generates a reminder_enqueue, which goes beyond pure routing and makes the coordinator part of reminder creation workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example uses Chinese-only natural-language strings in the top-level comment and payload fields such as studentAlias, subject, knowledgePoint, status, and note. For a general schema example, this implies a fixed language/locale without offering opt-in or documenting that the example is specifically region-scoped, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema is a manifest/config-type file, so SQP-3 applies. The top-level description is entirely in Chinese and the protocol also encodes Chinese-only natural-language enum values elsewhere, which imposes a specific language/locale without any user choice or explicit region-specific justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational instructions exclusively in Chinese, which effectively forces a specific language for users of the skill. Under the policy rule, locale or language restrictions should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill content is written in Chinese and includes no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Line L11 instructs the skill to use '一句话说明原因', and the entire shared guidance is written as mandatory Chinese interaction policy for student-facing behavior. There is no indication that users may choose another language or locale, so this creates a natural-language locale policy constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states the library is designed for '中国大陆的中文 K12 场景' and sets simplified Chinese content and mainland emergency channels as defaults. This is a natural-language locale policy constraint that applies broadly, and the file does not present it as a user choice or opt-in within the skill behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document is written as a mandatory repository-wide source of truth and uses Chinese-only terminology, stating that all related skill materials and schemas must reference this file. That creates a language policy constraint without offering users or downstream skill authors a language choice or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest frames this skill as a router/coordinator that does not itself analyze, but this section defines health indicators and interpretation thresholds for judging whether the user's learning system is healthy. That is a substantive evaluative capability rather than pure routing or mechanical aggregation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest says the coordinator only decides which skill should handle the request and does not itself retrieve or analyze content. Here, the example has the coordinator initiate note lookup and present specific retrieved note content back into the interaction, which blurs the promised boundary between routing and content-handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language content in the JSON $comment is entirely in Chinese and presents the protocol example as if Chinese is the required language, with no indication that other languages are allowed or that the locale is region-specific. Under the policy for natural-language violations, this can be read as a language/locale constraint without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language comment on L02 is written entirely in Chinese and the example payload also uses Chinese content, which suggests a language-specific convention. For a generally applicable schema example, this can conflict with language/locale policy unless the locale restriction is explicitly justified or the user is offered a choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON example includes a natural-language comment describing protocol roles, but it does not specify any explicit trigger conditions, scope limits, or exclusion cases for when a subject_profile_writeback handover is appropriate. In a manifest/config-style file, that lack of specificity can make activation or use conditions overly broad or open to interpretation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The only explanatory natural-language text in the file is written in Chinese, with no alternate language or indication that language choice is optional. If this skill ecosystem is expected to support broader organizational language preferences, this can constitute a locale/language policy issue because the file effectively forces one language for understanding the protocol note.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The comment explicitly states that xiaozhi-skill-coordinator only defines the protocol, validates format, and routes, and 'does not send writebacks'. However, this file is itself a teacher_writeback example containing writeback-oriented data structures, which creates an intent/documentation contradiction in the file context. Even if intended as a protocol example only, the comment is phrased broadly enough to conflict with the concrete writeback example immediately below.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON example embeds natural-language content entirely in Chinese, including the top-level comment and payload fields such as subject matter descriptions and root-cause text. For a generally applicable schema example, this can indicate a locale/language policy constraint without any visible opt-in or documented justification in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.