Back to skill

Security audit

试听与学员建档

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Chinese-language teacher intake workflow that stores limited student onboarding records with consent and clear boundaries, though users should localize it before use outside mainland China.

Install this only for a Chinese-language independent-teacher K12 intake workflow. Before using it in another region, localize crisis resources, consent-age assumptions, curriculum references, and enum values. Treat the stored records as minor student data: confirm guardian consent, avoid real names/contact details, and review any course-package or follow-up drafts before saving or sending.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The distributed schema grants this intake-only skill write access to coursePackageLedger and progressEvidence, even though the skill description says its scope ends at consent, intake, diagnosis, and creation of a minimal student profile. That mismatch violates least-privilege boundaries and could let the skill create or alter downstream business and assessment records outside its stated purpose, increasing privacy and integrity risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema note explicitly claims the copy was trimmed to the skill’s declared read/write scope, but the writable paths include records outside the intake workflow. This kind of scope attestation mismatch is dangerous because reviewers and downstream enforcement may trust the note while the actual permissions remain broader, enabling unauthorized writes under misleading documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and presents the skill's invocation and behavior only in that language, with no indication that other languages are supported or that the user can opt into Chinese. Under the policy, forcing a specific language or locale without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Across the markdown instructions, triggers, examples, and user-facing phrases, the skill consistently assumes Chinese-language interaction and does not mention any alternative language handling. This can amount to a language policy violation unless the Chinese-only scope is explicitly documented and justified or the user is given a language choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill's scope ends at intake and explicitly excludes follow-up for renewal, churn recovery, and related parent communication, yet this file is dedicated to post-trial conversion follow-up scripts over days 1-7. Even though the file tries to limit itself to drafting only, it still operationalizes parent follow-up after the trial, which goes beyond the manifest's stated '范围到建档为止' boundary.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L05 states that after enrollment-related follow-up is not in the intake skill and that related scenarios should be handed to other skills, but the rest of the file contains concrete follow-up cadence and scripts for converting a trial into signup. This is an active contradiction between the file's own scoping language and the behavior/documentation it actually provides.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template instructs collecting availability data even though the skill description says scheduling is out of scope and delegated elsewhere. This creates scope creep and unnecessary collection of personal routine information, increasing privacy exposure and the chance that the intake skill is used to perform scheduling-adjacent processing without the safeguards or boundaries intended for the dedicated scheduling skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Including course-package ledger fields expands the skill from profile creation into enrollment and package management, despite the manifest stating renewal-related handling is out of scope. That mismatch can cause unauthorized retention of commercial/enrollment data, confuse downstream automation, and let this skill influence billing or renewal workflows it was not meant to control.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file defines status changes, retention prompts, and deletion workflow, which materially extends behavior beyond simple profile creation. Lifecycle-management logic is security-relevant because mistakes can cause improper retention, premature deletion, or unauthorized record modification, especially when the skill is supposed to stop at creating the formal profile.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template expands a 'minimal intake' flow into adjacent processing domains by collecting availability, communication preferences, retention dates, and course-package ledger fields. Even without direct contact details, these fields increase data linkage and purpose creep, making the student profile more persistent and more useful for downstream tracking than the manifest's stated '建档为止' boundary suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This file presents all user-facing instructional content in a single language, which can violate a language/locale policy when no opt-in or alternative is provided. There is no indication that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

该文件全文以中文撰写,并以规范性措辞定义 SKILL 的行为,但没有说明这是仅适用于中文教学场景,或允许根据用户偏好切换语言。按规则,强制特定语言而无用户选择或正当、明确的区域限定,属于自然语言层面的语言/locale policy 风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest/schema includes natural-language instructions entirely in Chinese and later constrains user-facing enum values such as weekdays and communication preferences to Chinese-only strings. Under the policy, forcing a specific language or locale without user opt-in or a clearly documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description documents a general workspace covering multiple post-intake teaching operations, while this file is specifically distributed to the intake skill whose manifest excludes scheduling, lesson records, homework tracking, renewal/reporting, and contact handling. That documentation mismatch can mislead integrators about what this skill is intended to manage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The dayOfWeek field only accepts Chinese weekday names (周一–周日), which forces one locale for data entry and interoperability. There is no accompanying indication that this is a region-specific schema or that alternative locales are supported.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guardianCommunicationPreference field permits only Chinese-language option strings, which imposes a specific language/locale in the schema itself. The file does not provide opt-in language selection or a documented business need for this locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, beginning with the title on L01, and nowhere indicates that language selection is optional or limited to a justified region-specific use case. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest emphasizes minimal collection and no contact information storage, but this file extends the profile with communication-mode preference and parent-communication permissions. While not direct contact identifiers, these are additional communication-management attributes that go beyond a narrow diagnostic intake and approach follow-up workflow support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document states the library is designed for simplified Chinese K12 use in mainland China and defaults safety/help channels to that region. This is a natural-language locale policy constraint that could conflict with organizational requirements unless users or deployers explicitly opt in to that locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.