Back to skill

Security audit

Upwork 投标判断助手

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language Upwork bid-advice skill that uses user-provided job and profile information, without executable code or hidden account access.

Install only if you want a Chinese-language Upwork bid-evaluation assistant and are comfortable sharing job pages plus selected freelancer profile details such as skills, work history, rates, availability, and preferences. Do not provide passwords, cookies, verification codes, identity documents, bank details, exact address, or unredacted private client information.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states the skill is '面向中文自由职业者' (for Chinese freelancers), which is a natural-language locale/language constraint. Under the policy, forcing or hard-scoping a specific language or locale without opt-in or clear justification should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents all user-facing policy and safety instructions exclusively in Chinese. Under the policy rules, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction '默认中文' sets a specific language/locale by default, and the file does not offer the user a choice or require opt-in before enforcing Chinese output. Under the policy, forcing a language without user selection is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest presents the skill name, description, and default prompt entirely in Chinese, and the default prompt instructs the interaction in Chinese without offering a language choice. That can violate language/locale policy when users are not given an explicit opt-in or alternative language option.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation without any stated scope, trigger constraints, or exclusions. That can cause the assistant to activate this skill in conversations where the user did not clearly intend Upwork-specific analysis, potentially pulling the interaction into profile/job evaluation workflows and increasing the chance of unintended data collection or irrelevant guidance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation instructs users to provide an Upwork freelancer profile so the agent can build a persistent user profile, which expands the data collection scope beyond the declared purpose of evaluating a specific job posting and client risk. This creates a scope-creep/privacy risk because the agent may ingest broader personal and work-history data than necessary, increasing the chance of unnecessary retention, secondary use, or misuse of profile information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template requests personal preference and operational details such as minimum acceptable rate, weekly availability, time zone, and willingness to use tracking or attend video interviews, which are not strictly required for analyzing job/client risk as described in the skill metadata. Collecting these extra attributes broadens profiling of the user and can expose sensitive business preferences that could be mishandled or used outside the original decision-support context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Lines L06-L08 label the repository/skill as a Chinese Upwork bidding assistant and include a chinese topic, which signals a fixed language constraint. Because the document does not mention any user language selection or justified region-specific requirement, this appears to violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese, and nowhere indicates that the skill is China-specific or that users may choose another language. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire instruction file is written in Chinese and includes imperative workflow requirements, but it does not state that Chinese is optional, user-selected, or required for a region-specific purpose. Under the policy rule, a skill that effectively enforces a specific language without opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and instruction text require responses in Chinese and specify a fixed output format, but there is no opt-in or alternative language option. This can violate language/locale policy because it forces a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L11 states '使用英文为主' ('use English as the main language'), which is a language-policy constraint expressed as a recommendation without any user opt-in or alternative locale choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file presents all operational instructions in a single forced language without stating that the user may choose another language. That can violate language/locale policy when a skill effectively requires a specific language absent user opt-in or a documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural language entirely in Chinese across the substantive changelog entries. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file does not indicate an optional language choice or region-specific justification.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 36)May include surrounding context.

text
6. No warranty
   THE MATERIAL IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
   IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS
   FOR A PARTICULAR PURPOSE, ACCURACY, NON-INFRINGEMENT, OR RESULTS. THE AUTHORS
   ARE NOT LIABLE FOR ANY CLAIM, DAMAGES, LOST INCOME, ACCOUNT ACTION, OR OTHER
   LIABILITY ARISING FROM USE OF THE MATERIAL.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all user-facing guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, with no indication that language selection is optional or limited to a Chinese-speaking context. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill file is written in Chinese and provides no indication that users may choose another language or that the language restriction is required for a region-specific compliance purpose. Under the policy, a skill that effectively imposes a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.