Back to skill

Security audit

小菲学姐文科辅导

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a language tutor, but it explicitly offers to make AI-generated work harder to detect, which is not appropriate for an education skill.

Review this carefully before installing in an educational setting. The tutoring content is ordinary and the package does not appear to run code or access private data, but the AIGC detection-reduction feature should be removed or disabled if academic integrity, disclosure, or school policy compliance matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are broad, generic study terms such as 'preview', 'review', 'textbook', and 'essay help', which can cause the skill to activate in many ordinary educational conversations where the user did not explicitly request this tutor. Over-broad activation increases the chance of unintended prompt injection surface, context hijacking, or inappropriate takeover from more suitable domain-specific skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly markets help to 'reduce AIGC detection risk,' which goes beyond normal tutoring or editing and facilitates evasion of academic or institutional oversight. In an education-focused skill, this materially increases misuse risk because it can help users disguise AI-authored work as original student work.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Advertising rewriting to reduce AI-generated-content detection directly frames the feature as evasion assistance rather than educational support. This is dangerous because it can be used to conceal policy violations, academic dishonesty, or undisclosed AI authorship under the guise of 'polishing.'

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The English description repeats the same evasion capability in softer wording, indicating intentional product positioning around avoiding AIGC detection. In the context of a tutoring skill, this makes the skill more dangerous because it normalizes concealment of AI assistance in student submissions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The 'cross-module auto-association' feature describes automatic behavior that links different learning areas without clear user consent or scope limits. Ambiguous auto-triggering can cause the skill to expand beyond the user's immediate request, creating predictability and control issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains very broad study-related terms such as 'preview,' 'review,' 'textbook,' and 'grammar,' which are common in ordinary conversations. Overly broad triggers can cause unintended activation and route users into this skill when they did not intend to invoke it, increasing the chance of inappropriate or unexpected behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very broad generic terms such as '文科', '诗词', '作文', and '英语', which are common subjects and may cause the skill to activate in many unrelated conversations. This can lead to unintended routing, user confusion, and potential interception of requests that should go to other skills or default handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file begins with a Chinese-only title and the overwhelming majority of the content is written in Chinese, effectively imposing a specific language on users. Under the stated policy, language constraints should either be optional for the user or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file consistently presents the skill's output templates in Chinese, with only limited bilingual headings, which signals a default language requirement. Under the policy rule, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file invites 'all forms of contributions' without any limiting context, examples of exclusions, or specific trigger scope. Under the vague-trigger rule for markdown files, such broad language can create ambiguity about what kinds of contributions are actually appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README presents the skill as explicitly Chinese/English-focused and uses fixed bilingual language branding, textbook alignment, and examples, but does not state that users can choose their preferred language or locale. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.