Back to skill

Security audit

Qiaomai Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Chinese-language utility package for agent memory, knowledge graphs, task execution, case search, and report generation, with no evidence of hidden installation, network exfiltration, or persistence hooks.

Install this only if you are comfortable with a Chinese-language agent utility package and intentionally want memory-style data structures. Treat memory exports as sensitive because they can contain user-provided content; review what is stored before sharing or syncing it elsewhere.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Providing documentation only in Chinese can prevent many users, reviewers, and administrators from understanding the skill's capabilities, data handling, and optional third-party integrations. In a security-sensitive context, reduced comprehensibility weakens informed consent, deployment review, and safe configuration, especially when the skill includes persistent memory and external API options.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly advertises cross-session memory, persistent learning, and knowledge accumulation, but does not warn users that their data may be retained across sessions and elevated into longer-term memory layers. This creates a meaningful privacy and consent risk because users may disclose sensitive information without understanding that it could persist beyond the current interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language descriptions and output strings that assume Chinese as the only supported language. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The report generator emits all headings, labels, and recommendations in Chinese only. Because this is user-facing natural-language output and no language choice or explicit regional justification is provided, it conflicts with the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This codebase uses Chinese-only natural-language descriptions, prompts, and user-facing responses, which effectively forces a specific language experience. The file does not provide any opt-in, fallback, or documented justification for a Chinese-only locale, matching the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The intent patterns are overwhelmingly Chinese-specific, so users in other languages are not given equivalent support or a choice of locale. Because this language restriction is embedded in the activation logic and not explained as a justified regional limitation, it constitutes a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The printed setup wizard messages and generated assistant responses are all presented in Chinese, which imposes a specific language on users. The file contains no mechanism for selecting another language and no justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring and function signature imply that quick_setup(scenario) applies the caller-provided scenario, with a fallback to full when invalid. In reality, the method discards the scenario value entirely and calls interactive_setup(), which hardcodes selected = "research", so the effective behavior contradicts the documented intent of scenario-based quick setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The module title and all human-readable docstrings/comments are written in Chinese, with no indication that other languages are supported or that the locale is intentional and constrained. Under the policy, language-specific behavior should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The sync_to_external method exports all memories from selected layers and returns the raw exported dataset without any authorization check, consent flow, destination validation, redaction, or audit controls beyond a simple history record. In a memory system that may store sensitive prompts, user data, or long-term context, this creates a clear data exfiltration path if the method is invoked by an untrusted caller or misused by another component.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings, docstrings, log messages, and console output entirely in Chinese, including the module title and operational messages. That imposes a specific language/locale on users and operators without opt-in or justification, which matches the policy-violation category for language constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module’s natural-language description is entirely in Chinese and presents the skill as a Chinese-language reporting system without offering any language choice or documenting a justified region-specific constraint. This can violate language/locale policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The method is named _to_pdf and its docstring says '生成 PDF', which conveys that callers will receive PDF output. However, the implementation explicitly returns Markdown text encoded as bytes, so the documented/exported behavior contradicts the actual output format.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese, which indicates a language-specific user experience without any stated opt-in or alternative language choice. Under the language/locale policy, this is a natural-language constraint that should be explicitly optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains top-level documentation entirely in Chinese, and the skill presents itself as a general-purpose dynamic knowledge graph rather than a region-specific tool. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language strings such as the exception message, inline labels, and printed demo text are user-visible and consistently Chinese-only. Because the file does not offer alternative locales or explain a required Chinese-only context, this conflicts with the language-choice policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring on find_path states 查找实体间的路径(BFS), implying an unweighted breadth-first search. The code immediately below initializes distance tracking and a priority queue, and the comment explicitly says Dijkstra 算法, which is materially different behavior because edge weights influence the chosen path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.