Back to skill

Security audit

家长沟通助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, teacher-facing drafting aid for parent communication, with scoped workspace reads and a limited communication-log write.

Install this for Chinese-language, China-mainland K12 teacher workflows where persistent communication logs are acceptable. Do not use it unchanged for other countries or languages until emergency contacts, academic standards, and legal/data defaults are localized.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file hard-codes a China-mainland Chinese K12 scope and states that deployments to other regions should not be used directly unless operators localize emergency contacts, academic standards, and legal defaults. This is not an exploit primitive by itself, but it is a real safety/compliance weakness: if the skill is used outside its intended region without explicit gating or user choice, users may receive mismatched safeguarding guidance, legal assumptions, and educational framing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schema’s natural-language note and many enum values are exclusively in Chinese, which imposes a specific language/locale in the skill data contract. The file does not indicate that this is an optional locale, user-selected preference, or a clearly justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This file contains user-facing protocol instructions exclusively in Chinese, and there is no indication that users may opt into another language or that the restriction is explicitly justified as a region-specific policy. Under the language/locale policy rule, forcing a single language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.