Back to skill

Security audit

历史教案设计

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 history lesson-planning skill with disclosed classroom-data use and no executable or hidden system-level behavior.

Install this for Chinese mainland K12 history lesson planning where teachers review outputs before use. Do not treat generated sources, lesson plans, or crisis-referral numbers as globally valid without local verification and localization.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This shared document governs AI-generated test/question validation, which is outside the declared scope of a history lesson-planning skill that explicitly does not handle assessment or item-writing tasks. While not overtly malicious, including out-of-scope shared instructions can cause unintended activation behavior or bleed assessment-generation rules into lesson-planning flows, increasing the chance the agent performs tasks it should redirect away from.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The note field is written entirely in Chinese and presents operational constraints as fixed instructions, which effectively imposes a specific language context. The file does not offer any language choice or document a justified region-specific limitation, so this matches the policy's language/locale violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema description is entirely in Chinese and defines the contract in a single locale, with no indication that users can choose another language or that the locale restriction is intentional and justified. Under the stated policy, forcing one language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains end-user-facing policy/instruction content only in Chinese, with no indication that users may choose another language or that Chinese is required for a documented regional deployment. Under the language/locale policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document is entirely written in Chinese and presents operational guidance for skills without any indication that language choice is optional or user-configurable. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This reference resource forces a single language presentation across the whole file, and there is no indication that users may opt into another language or that the Chinese-only constraint is required for a region-specific purpose. Under the stated policy, language-only content without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

L11 明确规定“本库按中国大陆的中文 K12 场景设计”,并默认示例、话术和求助渠道均为中国大陆。这构成了自然语言层面的语言/locale 默认约束;虽然后文说明了跨地区部署需本地化,但该文件本身仍设定了默认地域与语言。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.