Back to skill

Security audit

独立教师工作台

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only teacher dashboard for a defined student workspace; it handles sensitive student records, but its access is disclosed and aligned with that purpose.

Install only for an authorized teacher/operator who is allowed to view the student workspace. Treat dashboard outputs and especially full workspace exports as sensitive records; do not deploy outside the stated Mainland China Chinese K12 context until crisis contacts, curriculum assumptions, and privacy/legal defaults are localized.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The documentation says the skill does not generate shareable outputs such as parent-facing content or reports, yet nearby text says it may generate shareable content after checking consent. That inconsistency can cause downstream agents or users to rely on the safer claim while the skill still produces externally shareable material, increasing the chance of unauthorized disclosure or policy bypass.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill repeatedly presents itself as a read-only dashboard, but these lines explicitly allow viewing and exporting the full workspace record. In a workflow handling minors' educational, parental communication, and consent data, this materially expands the data exposure surface and can bypass the user's expectation that the skill only summarizes minimal information needed for the dashboard.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template forces a specific language/locale for all user-facing content, including headings, instructions, and example output. Under the policy, language constraints should either offer user opt-in/choice or be clearly justified as region-specific; this file does neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file hard-codes a China-mainland Chinese K12 baseline and states it should not be used for students elsewhere unless operators localize emergency contacts, curriculum assumptions, and legal defaults. If reused in another region without explicit locale detection or user opt-in, the agent may provide wrong crisis resources, age/consent assumptions, or culturally mismatched educational guidance, which is a safety and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The privacy/data-control commands are specified as natural-language phrases such as '删除我的档案' and '暂停提醒' without requiring an explicit command mode, confirmation pattern beyond deletion, or disambiguation rules. In a conversational system, this can cause unintended activation from ordinary dialogue, quoted examples, or third-party text, leading to accidental privacy actions or suppression of memory/reminder behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown section instructs the skill to surface parent communication reminders and references consent gating, but it does not include any user-facing warning that the dashboard may display sensitive student and parent communication data. Under SQP-2 for markdown files, descriptions that affect privacy should disclose that behavior clearly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown sample forces a specific language/locale throughout the file, including headings, examples, and instructions, with no indication that users can opt into another language. Under the natural-language policy rule, a fixed language without user choice can be a locale-policy violation unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The schema allows English weekday values such as "Monday" through "Sunday" in day_of_week, while the surrounding schema text and descriptions are otherwise Chinese and state "中文优先". This introduces a language/locale policy inconsistency in a shared data contract without an explicit user choice or documented user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.