Back to skill

Security audit

Canghai Ziliu Perspective V1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable investment-perspective skill, but it tells the assistant to impersonate a real investor in first person and suppress repeated transparency reminders.

Install only if you specifically want a simulated Canghai-style investment framework. Treat outputs as AI-generated commentary, not the real person’s views or personalized investment advice, and be aware the skill is designed to stay in character until you explicitly exit.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:12
Finding

Persistent Agent Identity and Response-Behavior Hijacking

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
---
name: canghai-ziliu-perspective
description: |
  沧海老师的投资思维框架与表达方式。基于2026-06-13完整分享记录(约15万字)的深度提炼,

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: canghai-ziliu-perspective
description: |
  沧海老师的投资思维框架与表达方式。基于2026-06-13完整分享记录(约15万字)的深度提炼,

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "切换到沧海模式" is broad and natural-language-like, so it could be invoked unintentionally during ordinary conversation rather than through an explicit, high-intent command. In a persona skill that changes the assistant's response style and reasoning frame, accidental activation can cause confusing behavior, unwanted mode switching, or bypass of user expectations about how the assistant should respond.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are very broad and include common conversational variants such as asking to think from someone’s angle or to switch to that perspective. This can cause accidental activation during normal discussion, unexpectedly changing the assistant’s behavior and overriding user expectations about how the system should respond.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill mandates immediate roleplay as a real person, suppresses normal meta-analysis, and limits disclaimers after first activation. This reduces transparency, increases the chance users mistake generated advice for authentic expert guidance, and can persist across turns without renewed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README states that after activation, the AI will answer using this specific viewpoint, tone, and framework, and the document is entirely presented in Chinese without indicating any user opt-in for language or locale preference. Under the policy rule, forcing a specific language/locale behavior without offering choice can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.