Back to skill

Security audit

作业设计师

Security checks for vulnerabilities and agentic risk

Overview

This teacher-facing homework design skill is coherent and disclosed, with expected handling of class-learning records and no executable or remote behavior found.

Before installing, confirm this will be used in the intended Chinese K-12 teacher workflow and that your platform enforces the stated read/write boundaries, especially that this skill can only write homework records and aggregated completion summaries. Treat reviewPlans and examBlueprints as sensitive context and avoid entering unreleased official exam materials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The frontmatter description includes multiple generic teacher utterances such as '帮我设计一份一次函数的作业' and '出一份分层练习', which are broad enough to match normal discussion rather than an explicit request to invoke this skill. In a multi-skill agent, this can cause unintended activation, leading to unnecessary access to class workspace data or steering the conversation into assignment-generation when the user may only be asking generally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger section defines many activation phrases and routing rules, but several conditions remain semantically broad, especially around '复习作业', '反馈模板', and '作业批改', which can overlap with other teacher workflows. Ambiguous routing increases the chance of the wrong skill activating and processing sensitive educational context or producing outputs outside intended boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference file includes concrete multi-day review and exam-prep templates even though the skill metadata explicitly says this skill should not do review planning. That mismatch can cause the agent to drift into out-of-scope behavior, violate routing boundaries, and generate unsupported study plans when prompted or when retrieving reference material.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema copy distributed to the assignment-designer explicitly includes the examBlueprints path, even though the skill description says it should not design exams. This creates an unnecessary authority/data exposure mismatch: a compromised or over-permissive skill could read or write exam-design structures outside its stated purpose, violating least privilege and enabling cross-skill interference.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The distributed schema also includes reviewPlans, despite the skill metadata stating review scheduling belongs to another skill. This broadens accessible data and actions beyond the declared scope, increasing the chance of unauthorized modification of review schedules or inappropriate data coupling between skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Granting the assignment-designer access to the full examBlueprint structure exposes detailed assessment design data, including item definitions and teacher-verification workflow fields, that are unrelated to homework generation. In this skill context, that overexposure is more dangerous because the manifest expressly says the skill should not create exams, so the schema enables capability creep and potential unauthorized reading or tampering with high-value academic assessment content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Providing full reviewPlan structures gives the assignment-designer access to scheduling phases, spaced review dates, and interleaving sets that belong to a separate review-planning function. Because the skill is not supposed to perform review scheduling, this unnecessary access increases the blast radius of prompt injection, logic bugs, or unauthorized writes that could disrupt instructional planning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire document is written in Chinese and defines skill behavior and defaults for Chinese school grade bands, with no indication that users may choose another language or locale. This constitutes a natural-language locale constraint that is not presented as optional or explicitly justified within the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema embeds user-facing natural-language descriptions entirely in Chinese, including the scope note and top-level description. Because the file does not indicate that the skill is China-specific or otherwise intentionally restricted to Chinese users, it may violate language/locale policy by forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.