Back to skill

Security audit

排课与课时管理

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language scheduling helper for independent teachers that uses limited workspace records and requires teacher confirmation before changes.

Install this only if a Chinese-language independent-teacher scheduling workflow fits your use case. Before use, confirm the teacher understands that it stores schedule and course-hour records, relies on aliases rather than real names, and requires consent before cross-skill sharing or profile persistence. For users outside Mainland China, localize the crisis/help-channel guidance and legal consent assumptions first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill guidance is written as mandatory operational instruction in Chinese, and it does not indicate that users may choose another language or that the skill is limited to a China-specific deployment context. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L11 states the repository is designed for '中国大陆的中文 K12 场景' and fixes curriculum alignment, language, and default safety help channels to Mainland China. This is a natural-language locale restriction, and the file does not present a user-facing choice or opt-in mechanism within this content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The heading and core instructions define the shared vocabulary entirely in Chinese and state that all SKILL.md, references, and schemas must reference this file as the sole source of terminology. This imposes a specific language/locale on downstream skills without any opt-in, alternative language path, or stated region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown skill file presents its description, triggers, instructions, and user-facing examples only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without offering user choice can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file presents all operational instructions, templates, and warnings exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file contains user-facing operational guidance exclusively in Chinese, including critical safety instructions and hotline guidance. Under the policy, forcing a specific language without offering user choice can be a natural-language locale violation unless clearly justified as region-specific; while parts of the content discuss China-specific routing, the document also states it applies broadly to any skill encountering student distress.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The day_of_week field explicitly permits both Chinese and English weekday values and states that Chinese is preferred, while other user-facing schema values elsewhere are predominantly Chinese. This creates a locale policy concern because the skill imposes a language preference in natural-language schema content without documenting user choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.