Back to skill

Security audit

历史命题与答题规范指导

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 history-teacher assessment skill with disclosed data boundaries, confirmation steps, and no executable or hidden behavior found.

Install this for mainland China Chinese K12 history-teacher assessment workflows. Do not use it unchanged for other countries, languages, or curricula; localize crisis contacts, legal assumptions, and curriculum references first. Teachers should also verify all AI-generated questions, sources, and scoring rubrics before classroom or exam use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description is entirely written as Chinese-only guidance for activation and use, and the file does not state that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This schema is written as a general shared data contract, but its natural-language descriptions require Chinese-only terminology and references, such as the vocabulary source and educational labels. Because the file does not offer a language/locale choice or clearly justify a China-specific scope, it creates a locale policy issue for broader deployments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire protocol is written exclusively in Chinese and includes fixed Chinese-language response examples and hotline phrasing, without offering any user language choice or opt-in. Per the policy, forcing a specific language or locale without explicit user selection is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational guidance and constraints exclusively in Chinese, which can amount to a language/locale policy restriction if users or downstream skill authors are not given an explicit language opt-in. The file does not state that it is intended only for a Chinese-speaking or China-specific context, nor does it offer an alternative language path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The entire shared guidance is written in Chinese and includes prescribed user-facing phrasing such as the exact question in L14 and explanation wording in L11/L34, but it does not indicate that the user may choose another language. This can amount to a language-policy constraint without opt-in, especially because the file appears to standardize response behavior across skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L11 明确声明“本库按中国大陆的中文 K12 场景设计”,并将示例话术与安全求助渠道默认绑定到中国大陆中文环境。这属于自然语言层面的语言/locale 约束;虽然 L13-L17 提到跨地区部署需先做本地化,但该文件本身并未向最终用户提供语言或地区选择机制。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document establishes repository-wide required vocabulary and references entirely in Chinese as the single source of truth, which functions as a language policy for dependent skills. Under the policy rule, forcing a specific language without user choice or an explicit justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown resource presents all instructions and guidance exclusively in Chinese, and there is no indication that users can select another language or that the skill is explicitly limited to Chinese-speaking users. Under the policy rule for natural-language constraints, forcing a single language without opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.