Back to skill

Security audit

每周学习复盘

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese K12 weekly learning review skill with clearly scoped data use, consent checks, and no executable or hidden installation behavior.

Install this only for the intended simplified-Chinese K12 learning-review setting. Operators serving other regions should localize curriculum assumptions, consent rules, and crisis-support contacts before student use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and all user-facing trigger phrases are written only in Chinese, and the skill title/content consistently assume Chinese interaction. There is no indication that the user may choose another language or that the skill is intentionally restricted to a Chinese-speaking region for compliance or domain reasons.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states the repository is designed for simplified Chinese K12 scenarios in mainland China and sets default help channels, curriculum alignment, and legal assumptions accordingly. This is a natural-language locale policy constraint that does not offer the user a language or regional choice within the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document defines the repository-wide vocabulary entirely in Chinese and states it is the sole source of terms and enums for all skills. This imposes a specific language on downstream skill content without indicating user opt-in, alternative locales, or a documented region-specific justification in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This file contains operational safety instructions exclusively in Chinese, which can create a language-policy issue if the skill is used in multilingual contexts without explicit user or operator opt-in. The policy allows fixed locale behavior when clearly documented and justified, but this file does not state that it is restricted to Chinese-language or China-focused deployments overall.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.