Back to skill

Security audit

英语听力材料设计

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent teacher-facing English listening lesson design skill with disclosed classroom data use and no executable or hidden install behavior.

Install this for Chinese K12 teacher workflows where class assessment and listening records may be available to the platform. Operators outside Mainland China should localize curriculum assumptions, legal guidance, and crisis resources before student-facing use, and teachers should keep the confirmation and consent controls enabled before writing items or student-profile updates.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and all instructional content are written entirely in Chinese, and the file gives no indication that users may choose another language or that Chinese is a required locale for a region-specific deployment. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructions and guidance exclusively in Chinese, and it does not indicate that the user opted into that language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This sample presents all instructional content only in Chinese and does not indicate any user language selection or justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents all instructions and examples exclusively in Chinese, with no indication that the user can choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The schema copy exposes multiple assessment-analysis datasets (itemScores, itemStats, weaknessRank, reviewPlans) to a skill described primarily as listening lesson design. Even where some are read-only, over-broad data exposure increases attack surface and enables unnecessary access to student performance analytics, making data misuse, prompt leakage, or unintended cross-function behavior more likely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scoped schema explicitly grants this listening-lesson design skill write access to examBlueprints, allowing it to create or modify assessment structures outside its described lesson-planning workflow. In an agentic system, unnecessary write capability expands the blast radius: a compromised or misaligned skill could alter exams, inject unverified items, or interfere with downstream assessment processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely written in Chinese and includes normative instructions for SKILL behavior, such as user-facing applicability and reminder rules, but does not state that language/locale is optional or limited to a China-specific deployment. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is entirely written as a normative shared policy file for skills, and several directives and examples assume Chinese-language interaction by default, including required one-sentence wording and skill behavior. Because no user language choice, opt-in, or documented locale limitation is provided, this can violate a language/locale policy requiring flexibility or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that the repository is designed for '中国大陆的中文 K12 场景' and defaults safety-help channels, curriculum alignment, and legal assumptions to Mainland China. This is a natural-language locale policy constraint, and the file does not offer user opt-in or selection within the skill itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written as normative instructions in Chinese and presents itself as the sole source of terminology and enums for the repository. There is no indication that users or downstream skill authors may choose another language or locale, which constitutes a language policy constraint without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.