Back to skill

Security audit

学情分析师

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese K12 teaching analytics tool that handles student performance records, but its sensitive behavior is disclosed, scoped, and teacher-controlled.

Install this for Chinese-language K12 teacher workflows where storing class assessment analytics is acceptable. Before use, confirm the platform's persistence and sharing controls are configured, use aliases rather than real student names, and localize curriculum, consent, and crisis-support guidance if serving users outside mainland China.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all instructions, templates, and usage guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is entirely written as a required template in Chinese, including prescriptive phrasing such as '一律' and fixed field labels, but it does not indicate that Chinese is optional or that the skill is limited to a Chinese-language context. This can violate language/locale policy when users or deployments expect language choice or neutrality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The distributed schema grants this analyzer visibility into lesson planning, homework, exam design, and review-planning structures even though the skill description says those functions belong to other skills. That over-broad data contract weakens separation of duties and enables an analyzer invocation to read or influence adjacent teaching workflows beyond its stated purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The scope note asserts the schema was trimmed to fields mentioned in non-negative context, yet the file still includes fields the manifest says should be handled by other skills. This mismatch is dangerous because security decisions may rely on the note, causing reviewers or enforcement code to trust a boundary that the actual schema does not honor.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema includes natural-language notes, descriptions, enums, and usage guidance exclusively in Chinese, such as the note in x-skill-scope and the top-level description. Under the policy, forcing a specific language without user opt-in or a clearly documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Exposing full lesson-plan objects to a student-analysis skill creates unnecessary authority over another skill’s domain. If the agent can consume or emit these structures, it may leak pedagogical content or make unauthorized modifications despite the manifest explicitly delegating lesson-plan work elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Exam blueprint structures contain assessment design details that are outside this analyzer’s declared scope. Their inclusion breaks least privilege and could allow a performance-analysis skill to access or shape test-construction data, undermining compartmentalization between analytics and assessment authoring.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Including review-plan structures in the analyzer schema broadens the skill’s reach into scheduling and intervention planning, contrary to the stated boundary that review planning belongs to another skill. This can let analysis outputs steer or overwrite remediation plans without proper handoff controls, increasing the risk of cross-skill privilege abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Lines L60-L66 repeatedly anchor the skill behavior to Chinese school-system structures and a China-specific policy document, such as 六三制、五四制 and 《中小学生成式人工智能使用指南(2025年版)》, and define defaults like '高中原生' based on that context. This is a natural-language locale policy constraint, but the file does not offer user opt-in or clearly state that the skill is only for the China education context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill file is written as mandatory operating guidance in Chinese and includes Chinese-only prescribed user-facing phrases, such as the exact question in L14 and explanation wording in L34. There is no indication that users may choose another language or that the locale restriction is justified as a region-specific skill, which makes this a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file hard-codes the library for mainland China Chinese K12 use and states it should not be directly used for students in other regions unless operators first localize emergency contacts, curriculum alignment, and legal settings. In an education skill that may handle minors' data and safety guidance, this default can cause mislocalized crisis resources, age-of-consent assumptions, and regulatory mismatches if deployed elsewhere without explicit user-region confirmation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.