Back to skill

Security audit

Yingzhong Smart Teacher Main

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent teacher assistant, but it asks to handle and persist sensitive student, parent, academic, and emotional data with broad automatic sharing and synchronization behaviors.

Review this skill before installing in a real school setting. It should only be used with clear school authorization, explicit consent and review for parent communications, disabled or minimized emotional profiling, defined retention and deletion rules, controlled sync and backup destinations, and safe handling for downloaded third-party documents.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:3658
Finding

Automatic Retention and Synchronization of Sensitive Student Data Without Defined Lifecycle Controls

Content
View full analysis
encrypted transmission -> school data center. Student data -> encrypted transmission -> school data center (parent may view it). All data has a local backup. Synchronized content: - Lesson plans: automatically synchronized - Student profiles: automatically synchronized - Correction records: synchronized in real time - Custom agent configurations: automatically synchronized Synchronization strategy: - Wi-Fi: real-time synchronization - Mobile network: synchronize critical data - Offline mode: cache locally and synchronize automatically when connectivity returns Cloud backup: Automatically back up to cloud storage every day. ``` ### Technical Analysis The skill instructs the agent to build persistent profiles containing student names, grades, learning history, emotional state, behavioral observations, family communications, and school information. These profiles are updated after interactions and may be synchronized automatically to a school data center and cloud backup. Although the document later claims that transmission and storage use encryption, it does not define: - The actual synchronization or backup endpoint. - The identity of the data controll ...[truncated 1863 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:2906
Finding

Identifiable Parent-Communication Records Stored as Plain JSON Files

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:3299
Finding

Batch Download of Untrusted Remote Documents Without Validation or Sandboxing

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (17)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
---
name: yingzhong-smart-teacher
version: 5.0.0
title: "营中智教助手 Yingzhong Smart Teaching Assistant"
description: "专为中小学教师打造的一站式AI智教助手 | 基于飞飞学伴v4.0全面升级 | 集成清华MAIC虚拟教室+ChinaTextbook教材库+OCR批改+微信家校通 | 营山中学×学来学去联合出品"
author: "营山中学 & 学来学去学习社 | Yingshan Middle School & Learn2study Club"
tags:
  - education
  - teacher-assistant
  - K12
  - smart-teaching
  - homework-correction
  - parent-communication
  - question-bank
  - academic-analysis
  - yingzhong
  - OCR
  - feifei-companion
  - HERMES
  - UCL
  - MIT48h
  - ChinaTextbook
  - MAIC
lang:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that learning reports are updated and parents notified of progress, but it does not clearly warn users that student performance information may be automatically shared onward. In a school setting, undisclosed automatic parent notification can expose sensitive academic or behavioral data and undermine informed consent and expected confidentiality.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The proactive AI section describes monitoring behavioral and emotional signals, predicting needs, and sending messages, but omits a clear warning that such monitoring and intervention occur. For minors, covert or poorly disclosed behavioral inference can be intrusive, manipulative, and privacy-invasive, especially when tied to emotional state or academic decline.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section describes detailed student profiling across cognition, knowledge, emotions, interests, habits, and goals without a clear upfront privacy warning, consent model, retention limit, or minimization standard. In a K12 context, that is especially sensitive because the data concerns minors and can be persisted, inferred, and shared with parents or school actors, creating material privacy and safeguarding risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The emotional memory system explicitly tells the assistant to remember sensitive disclosures, emotional triggers, and relationship signals for future reuse. For minors, storing and reusing such intimate information can intensify manipulation, confidentiality breaches, and harm if accessed by unauthorized parties or surfaced inappropriately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

OCR grading, student records, and class-management features imply handling of highly sensitive educational data, potentially including student identities, grades, handwriting, and performance history. The README presents these capabilities without any safeguards, warnings, or data-handling expectations, which is especially risky in a K-12 context where minors' data requires elevated protection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises parent communication and WeChat notification features without any warning about student/parent data processing, consent, retention, or transmission risks. Because these features inherently involve personally identifiable information and external messaging, lack of privacy guidance can lead to misuse, over-sharing, or non-compliant handling of sensitive school data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases listed are broad, natural-language commands such as '帮我备课', '生成教案', and '发通知', which could easily appear in ordinary teacher interaction and unintentionally activate the skill. In a school setting, accidental activation could cause unintended searches, content generation, or parent-facing actions, increasing operational and privacy risk.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill declares generic trigger keywords such as “预习 / 复习 / report / plan / English grammar,” which are common phrases in ordinary teacher or student conversation and not unique to this skill. Because the document does not provide exclusion conditions or a narrow invocation context, these broad terms could cause unintended activation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs persistent collection and onward sharing of student data through reports and parent communications. Even if framed as educational support, retaining and redistributing performance data without strict minimization, consent, and access controls creates a real privacy vulnerability, especially for minors.

Content

No source excerpt is available for this finding.

Indirect Prompt Extraction

Medium
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains patterns that could indirectly extract system prompts through rephrasing, translation, summarization, or side-channel techniques.

Content

Scanner excerpt · SKILL.md (reported line 1462)May include surrounding context.

md
### Level 3: 创造性主动 Creative Proactivity

**反向提示 Reverse Prompting:**
- "你最近在学物理力学,其实生活中到处都是例子:为什么过山车不会掉下来?"
- "诗词背累了?试试飞花令游戏,和同学一起玩更有趣"
- "你数学进步了,要不要挑战一下编程?逻辑思维是相通的"

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This profile-building section directs long-term collection of sensitive student attributes including emotional state, habits, interests, goals, and inferred learning styles. Persistent behavioral profiling of minors materially increases risk of misuse, over-collection, bias, and unauthorized disclosure, making the context more dangerous than ordinary personalization.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The combination of trust-building, emotional memory, and proactive outreach creates a gradual sensitive-engagement pattern in which the assistant can accumulate intimate knowledge and then use it to shape later interactions. In a K12 environment this is more dangerous because minors are more susceptible to persuasive, dependency-forming, or privacy-invasive engagement loops.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workbench presents short commands like “帮我备课”, “批改作业”, “分析成绩”, and “联系李四家长” as direct invocations, but these phrases are also normal requests a teacher might make in unrelated contexts. The file does not define boundaries for when these are treated as commands versus ordinary conversation, increasing the risk of accidental invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The custom agent configuration hardcodes "language": "zh-CN" without presenting language choice or documenting that it is optional. This creates a locale policy issue because the skill otherwise presents itself as bilingual and does not require explicit user opt-in before fixing the agent to a specific locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README labels the skill language as 'Chinese' and all invocation examples and operating guidance are presented only in Chinese, with no indication that users can choose another language. Under the policy, forcing a specific language without opt-in can be a natural-language policy issue unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.