Back to skill

Security audit

文言文教学指导

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese classical-literature teaching guide with scoped classroom-record handling and no executable, hidden, or destructive behavior.

Installers should understand that this skill is designed for Chinese-language K12 teaching in a mainland China curriculum context and may store or update classroom learning records only through the platform's consent and confirmation flow. Teachers should review generated lesson plans and translations before using them with students.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger section lists everyday-style phrases such as “古诗怎么上”, “古代文化背景”, and “文言文怎么翻译” as activation examples, but it does not clearly constrain when this skill should activate versus when related literature, translation, or general culture skills should not. Because the file provides examples but no negative examples or explicit boundaries in the trigger section, these phrases could overlap with common teacher requests and cause unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This reference file presents all instructional content in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The reference template explicitly includes per-section '重点句子' and '译为' fields, which encourages line-by-line explanation and translation of the source text. That directly conflicts with the skill's stated guardrails of not providing full serial explanation or complete modern-language translation, making it likely the agent will overshare disallowed instructional content when this template is followed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file states it is intended for use with this skill, but the sample format operationalizes behavior that contradicts the skill's declared restrictions. This kind of internal inconsistency weakens policy enforcement and can cause an agent to privilege the concrete template over the higher-level safety limits, resulting in unauthorized full explanations or translations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states domain terms and vocabulary are defined in Chinese, and the schema throughout constrains many values to Chinese-only enums. For a shared schema file, this is a natural-language locale restriction, and the file does not offer an opt-in language choice or explain a region-specific necessity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file’s instructions are entirely in Chinese and include directive language such as "请勿直接编辑", but there is no accompanying indication that language choice is optional or user-selected. Under the policy rule, forcing a specific language or locale without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L11 明确写明本库按“中国大陆的中文 K12 场景”设计,示例与话术为简体中文,安全求助渠道默认中国大陆。这属于语言/地域默认策略,且在该处没有提供用户选择或显式 opt-in,符合自然语言层面的语言/locale 政策违规特征。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

Lines L181-L183 require统一名称 and统一测评类型 using Chinese labels only, and the entire shared vocabulary is declared as the唯一术语与枚举来源. This imposes a specific language/locale on downstream skill content without offering a user language choice or stating a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file title and description are entirely in Chinese and specify a junior-high Chinese classical learning context, but they do not state that the skill is region-specific or offer any language/locale opt-in. Under the policy, fixed language assumptions in natural-language content can be a locale-policy issue when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file contains instructional content exclusively in Chinese, and there is no indication that users can opt into another language or that the language restriction is required by a clearly documented regional or compliance need. Under the policy rule for natural-language violations, forcing a specific language without opt-in is in scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file’s instructional content is entirely in Chinese and does not indicate any user opt-in, alternative language, or locale selection. Because SQP-3 applies to all file types and covers forced language constraints, this appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.