Back to skill

Security audit

SKILL 编写工具

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language SKILL authoring guide with disclosed China K12 defaults and no evidence of hidden execution, data collection, persistence, or destructive behavior.

Install this as a Chinese/China K12-focused SKILL development aid. Before using its templates in another region or language, adapt the curriculum assumptions, crisis/help channels, consent rules, and user-facing wording.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The frontmatter description is entirely in Chinese and frames usage through Chinese trigger phrases, implying the skill is intended to operate in Chinese only. Elsewhere the document repeatedly specifies Chinese student contexts, but it does not explicitly offer language choice or state a justified locale-specific limitation for the skill itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template explicitly states the skill is for Chinese middle-school students, which hard-codes a locale and audience in the prompt text. Similar locale-specific wording recurs across multiple templates without offering user choice or documenting a justified region-specific constraint, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This template specifies '面向中国初中生', which fixes the locale in natural-language instructions. The file does not consistently frame this as a region-specific compliance limitation or offer an alternative locale path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The schema's human-facing descriptive text is written exclusively in Chinese, including the scope note and top-level description, with no indication that the skill is intentionally restricted to Chinese-speaking users or that language choice is configurable. Under the policy for natural-language violations, this is a locale/language constraint presented without user opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states the repository is designed for Mainland China Chinese K12 scenarios, with simplified Chinese wording and default crisis/help channels for Mainland China. Although it includes deployment cautions for other regions, it still establishes a mandatory locale/language baseline rather than offering user opt-in or choice, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire shared vocabulary and operational terminology are prescribed exclusively in Chinese, with no indication that users may choose another language or locale. Under the policy rule, forcing a specific language without explicit user choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.