Back to skill

Security audit

测评设计师

Security checks for vulnerabilities and agentic risk

Overview

This is a teacher-facing exam design skill whose data use and regional scope are disclosed and aligned with its purpose.

Install this for Mainland China Chinese K12 teacher exam-design workflows. If used in another region or language, localize curriculum standards, consent/privacy assumptions, and crisis-resource contacts first; teachers should also review AI-generated questions manually before using them in real exams.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema is a manifest-type file, so natural-language policy checks apply. The schema uses Chinese-only descriptive text and constrains multiple user-facing values to Chinese terms, but it does not document that the skill is region-specific or provide any language/locale opt-in, which can violate a language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire shared skill guidance is written as prescriptive operational policy in Chinese, including required wording and interaction patterns, but it does not indicate that language choice should follow the user's preference or provide any opt-in. This can amount to a language/locale policy violation because it implicitly fixes the skill behavior to a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly sets the default operating context to Mainland China Chinese K12 and says deployments to other regions should not be used directly without prior localization. This is not code execution risk, but it is a real security/safety configuration weakness because it can cause the agent to provide region-inappropriate emergency contacts, legal assumptions, age-of-consent handling, and curriculum guidance when user locale is unknown or different.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file contains user-facing instructions and templates exclusively in Chinese, beginning with the title at L001 and continuing throughout the document. Under the policy rule for natural-language violations, forcing a specific language without an explicit user choice can be a locale/language policy issue unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.