Back to skill

Security audit

地理教案设计

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese, China-mainland K12 geography lesson-planning skill with scoped classroom data use and no executable install or hidden behavior.

Install this only for Chinese-language, China-mainland K12 geography lesson-planning contexts unless you localize curriculum references, consent rules, and crisis-support contacts. Review platform memory settings because the skill can read class teaching data and create pending lesson-plan records, although it discloses controls for viewing, correcting, deleting, pausing, exporting, and limiting sharing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema note is written as a mandatory operational instruction in Chinese and describes how the distributed copy must be used, without offering any language choice or opt-in. Under the policy, forcing a specific language/locale is a natural-language violation unless the locale restriction is explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description and terminology requirements are presented only in Chinese and direct consumers to use a shared Chinese vocabulary file, which effectively imposes a single language/locale. The file does not state that the skill is region-specific or that users may choose another language, so this conflicts with the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L11 明确写明“本库按中国大陆的中文 K12 场景设计”,并指定示例与话术为简体中文、安全求助渠道默认中国大陆。这是显式的语言和地区默认约束;虽然后文说明其他地区需先做本地化处理,但该文件本身仍强制了默认 locale,未体现用户可选择语言/地区的 opt-in 机制。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This file contains user-facing operational instructions only in Chinese, including crisis-handling language that may need to be understood accurately by operators or downstream users. The policy allows locale constraints when explicitly documented and justified, but this file does not clearly state that Chinese is required or offer an alternative language option.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.