Back to skill

Security audit

课后记录助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly scoped Chinese K12 teacher lesson-log assistant with disclosed workspace reads/writes, consent checks, and confirmation gates before records or lesson-unit changes are saved.

Install this for Chinese-speaking K12 teacher lesson logging where persistent student records and course-unit ledgers are expected. Before use, confirm consent settings, keep aliases instead of real names, review drafts before saving, and localize crisis/help channels and legal consent rules if used outside Mainland China.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill guidance is written as normative instructions in Chinese, including required response phrasing such as asking the user whether an exam is finished and giving a one-sentence reason. There is no indication that users may choose another language or that the Chinese-only constraint is limited to a region-specific deployment, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file explicitly scopes the skill library to Mainland China Chinese K12 use and defaults crisis/help channels to China Mainland unless operators localize first. This is not code execution or data exfiltration, but it is a real safety and product-security issue because users outside that region could receive inapplicable educational guidance or, more importantly, incorrect crisis-routing information if deployment controls fail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema contains natural-language strings, enums, and descriptions exclusively in Chinese, including operational status values and consent labels, but it does not document that the skill is intentionally limited to Chinese-speaking users or offer any language/locale choice. That can violate the language/locale policy for natural-language content because it implicitly forces one locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.