Back to skill

Security audit

教案设计器

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese K12 lesson-planning skill that uses class-workspace data to draft lesson plans with appropriate limits and controls.

Install this if you are using it for Chinese K12 lesson planning and are comfortable letting it read class summaries, weaknesses, and student-tier labels from the class workspace to draft differentiated plans. Teachers should confirm generated plans and AI-created exercises before use, and deployments outside Mainland China should localize curriculum assumptions and crisis-support contacts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description and metadata include broad trigger examples such as '写一份教案' and similar everyday planning requests that can match loosely-scoped user intent. This can cause the skill to activate when the user did not specifically want this planner, leading to incorrect routing, unnecessary access to classWorkspace context, and accidental use of dependent educational data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger table lists many common teacher requests and adjacent scenarios, but the boundaries are still soft enough that ordinary educational queries could invoke this skill instead of a more appropriate one. In a multi-skill environment, ambiguous routing increases the chance of unintended data exposure, mis-execution of workflow, and confusion when this skill reads student tiers or class summaries for a request that did not require them.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says this skill is for UbD-based lesson planning and explicitly says it does not create exam papers or related assessment-generation functions. This file is dedicated to validating AI-generated questions and example items, which aligns with exam-design behavior rather than lesson-planning behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains all operational instructions in Chinese and does not indicate that users may choose another language or that the skill is limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The note is written as an authoritative instruction entirely in Chinese and states that read/write permissions and authorization bits are determined by the Chinese SKILL.md. Elsewhere the schema also hard-codes Chinese-only enums and descriptions, but does not state that this skill is intentionally China-region-only or provide any language opt-in, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains operational safety instructions exclusively in Chinese, including critical crisis-response guidance. Under the policy, forcing a specific language without opt-in or a documented justification is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains only Chinese-language instructions and parameters, with no indication that users may choose another language or that the skill is explicitly limited to a Chinese-speaking context. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is reportable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Lines L004-L008 establish a repository-wide single source of truth in Chinese terminology, and later sections continue prescribing fixed Chinese labels and wording. This is a natural-language locale constraint presented as mandatory policy, with no indication of user opt-in or an allowed alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

该 markdown 文件全文以中文编写,并通过固定中文模板字段与话术示例引导使用者按中文输出,但未见提供其他语言/locale 选择,也未说明此限制仅适用于特定地区或用户群。根据规则,强制特定语言而无用户选择或明确正当化,属于自然语言层面的语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.