Back to skill

Security audit

班级错因分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese K12 math teaching aid that analyzes anonymized class error data and includes consent and privacy controls for student records.

Before installing, confirm this is being used in the intended Chinese K12 teaching context and that the platform enforces the included schema and consent gates, especially for teacher writeback, parent sharing, deletion, and any long-term student records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger section includes very broad phrases such as “学员错在哪里”, “哪个知识点没掌握”, and especially “下次课讲什么”, which can match ordinary teaching conversations outside the narrow prerequisite of having concrete wrong-answer data. This can cause the agent to activate the skill prematurely, route users away from a more appropriate skill, or encourage analysis based on insufficient evidence, leading to inappropriate handling of student performance data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions and examples exclusively in Chinese, including headings, notes, and operational guidance. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale/language policy issue when no alternative or opt-in is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema contains natural-language policy-relevant text entirely in Chinese and uses Chinese-only enumerated values and descriptions for operational concepts, beginning with the scope note on L007. Because the file does not indicate that the schema is intentionally region-specific or provide any user opt-in or alternative locale, it effectively forces a specific language/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description states '词表以 shared/vocab.md 为准', and the surrounding schema uses Chinese-only terminology for all key educational categories. That creates a language/locale constraint without an explicit opt-in or justification that this is a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file states that examples and phrasing are in Simplified Chinese and that safety-help channels default to Mainland China, framing the repository around a specific locale. Although it mentions operators should localize before deployment elsewhere, it does not offer end users a language/locale choice or opt-in within the skill behavior itself.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The privacy control entry phrases are intentionally broad natural-language triggers, but they lack clear scope constraints and disambiguation guidance. In a system that uses phrase-based activation, this can cause accidental invocation of sensitive actions such as viewing, exporting, pausing memory, or deleting records when a user is merely discussing those concepts rather than requesting them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Lines L004-L008 define this document as the single authoritative vocabulary source for all skills, and the prescribed terms throughout are exclusively in Chinese. Because the policy applies repo-wide and does not mention opt-in, alternatives, or locale-specific justification, it creates a language/locale policy constraint that could force a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire template, including headings and field labels, is written only in Chinese, which implies the skill expects or enforces a specific language. Under the policy, language-specific behavior should either offer user choice or clearly document a justified locale restriction; this file does not do so.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

该技能文件从标题开始即完全以中文编写,未见提供其他语言选项、用户选择机制,或说明其仅面向特定中文教学场景。按规则,强制特定语言而无用户 opt-in 可能属于自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill offers alternative language options or that Chinese is a required, justified locale. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.