Back to skill

Security audit

Mahjong AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Sichuan Mahjong assistant that analyzes user-provided tile photos and typed tile lists without hidden persistence, credential access, or unsafe execution behavior.

Install only if you want a Chinese/Sichuan Mahjong assistant. When sending hand photos, crop to the tiles and avoid incidental personal or location details; the package itself does not show hidden data collection, but image handling depends on the OpenClaw assistant platform you use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents the skill entirely as a Chinese-language assistant (e.g. title '麻将 AI 助手') and elsewhere describes Chinese-only tile naming and interaction patterns, but provides no indication that users may choose another language or locale. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to send photos of their Mahjong hands to the assistant, but it provides no disclosure about where images are processed, whether they are stored, shared with third-party AI services, or retained for training/logging. This creates a privacy and consent risk because users may transmit images that include incidental personal or environmental data without understanding the handling or exposure of that data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire reference guide is written in Chinese and uses Chinese tile names and descriptors without any indication that the skill is region-specific or that users can opt into another language. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file includes natural-language instructions and interface text that assume Chinese as the only supported language. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern unless the tool is clearly documented as region-specific or offers a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Throughout execution, the script prints all help, warnings, and analysis results in Chinese only. Because the file does not provide a user-selectable language or clearly justify a fixed locale in policy terms, this is a natural-language locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document title and all instructional content are written in Chinese, with no indication that users may choose another language or locale. Under the stated policy, natural-language content that effectively forces a specific language without user opt-in should be flagged.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.