Back to skill

Security audit

数学测评设计

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese K12 math assessment-design assistant with teacher-confirmed data use and no hidden code, network execution, or persistence mechanism.

Install only if you want a Chinese-language, China-curriculum-oriented math assessment workflow. Review tenant locale and student-data consent settings, because the skill can read limited class assessment context and write confirmed assessment summaries through the platform.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all instructional content are written entirely in Chinese, and the template is presented as the required format for use with the associated skill. There is no indication that users may choose another language or that the Chinese-only requirement is a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and the entire template are written as a Chinese-only workflow and output format, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The distributed schema explicitly grants read access to studentTiers even though the skill description says student stratification belongs to another skill and should not be handled here. This creates unnecessary access to learner segmentation data, violating least privilege and enabling the math exam designer to infer or use student grouping information outside its declared scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The schema grants read access to weaknessRank, which is tied to error diagnosis and learning weaknesses, while the manifest says this skill does not perform error classification or individualized diagnosis. This overexposes sensitive pedagogical profiling data and allows the exam-design skill to incorporate or leak diagnostic information beyond its intended function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest says this skill should only handle mathematics assessment design and explicitly excludes non-math subjects. However, the shared schema allows exam blueprint items such as 听力, 口语, 写作, 材料解析, and 论述, which are clearly broader than math assessment design and enable behavior outside the claimed subject-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document states the library is designed for '中国大陆的中文 K12 场景' and fixes examples, wording, and safety help channels to Mainland China by default. This is a natural-language locale constraint that applies broadly, and it is not presented as a user choice or opt-in at the point of use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language instructions require unified naming such as specific Chinese labels for the coordinator, assessment types, and copyright states, with wording like '统一名称' and '废弃' alternatives. This enforces a specific language/locale convention without offering user choice or documenting a region-specific justification, which matches the language-policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains only Chinese-language content and provides no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy issues in natural-language content. This file presents all instructions and guidance only in Chinese, with no opt-in, alternative language option, or explicit justification that the skill is region- or language-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.