Back to skill

Security audit

课堂互动教练

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese classroom-coaching skill that uses teacher workspace data for interaction planning and post-class notes, with no executable payloads or hidden data movement found.

Install this for a Chinese K12 teacher workflow where using class profile, lesson-plan context, and student tier/weakness summaries is acceptable. Review the workspace-sharing settings first, especially for student tier data, and use the documented pause, delete, and sharing controls when a class record should not be read, saved, or shared.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger section includes broad natural-language phrases such as '帮我设计课堂提问' and '学生不发言怎么办' that are common in ordinary teacher conversations and can cause the skill to activate when the user may only want a brief answer or a different tool. In a multi-skill environment, overbroad activation increases the chance of unintended data access to classWorkspace and unnecessary cross-skill workflow invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains end-user instructional content exclusively in Chinese, and nowhere indicates that users may choose another language or that the skill is restricted to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The scope note claims the schema was trimmed to retain only fields appropriate for this skill, but the retained paths still include lesson-planning and student-analysis data that the manifest says are out of scope. This misleading documentation is dangerous because reviewers, downstream agents, or policy enforcement systems may trust the note and approve broader access than intended, weakening defense-in-depth.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema exposes the lessonPlans path to this classroom-coach skill even though the skill metadata says it does not write lesson plans and delegates lesson-plan creation to another skill. This creates an unnecessary privilege boundary violation: if the skill or prompt logic is compromised, it could read or modify planning content outside its stated role, enabling unauthorized cross-skill data access or tampering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The schema grants access to studentTiers and weaknessRank, which are student performance-analysis fields, despite the skill description explicitly saying student analysis should be handled by xiaozhi-teach-student-analyzer. Even though aliases are used instead of real names, these fields still reveal sensitive educational profiling and allow the skill to infer, store, or manipulate assessment-derived classifications beyond its declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file establishes repository-wide terminology and usage rules entirely in Chinese and uses mandatory language such as '唯一术语与枚举来源' and '只能引用本文件的定义'. This is a natural-language locale policy constraint that forces a specific language across dependent skills without offering user choice or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and presents Chinese trigger phrases and usage expectations as the default, but does not state that language choice is optional or region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese, and there is no indication that the skill is limited to Chinese-speaking users or that another language option is available. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema includes natural-language descriptions, notes, and enumerated values entirely in Chinese, such as the scope note and workspace description, with no indication that the skill is region-specific or that users can choose another language. Per the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.