Back to skill

Security audit

资鉴问道

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed historical decision-support reference tool and does not show hidden data access, persistence, credential use, or unsafe execution.

Install this as a historical analogy and decision-reflection skill, not as a professional advisor. Keep its file access read-only and scoped to the bundled reference corpus, and treat its conclusions as perspective rather than instructions to act.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance says to trigger the skill when the user says things like 'should I…', 'help me think through this decision', 'how should I choose', or 'I'm facing this dilemma'. These phrases are common in ordinary conversation and the 'or otherwise wants historical reference for a real-life decision' language further broadens activation boundaries, making it unclear when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to read local reference files such as references/案例索引.md and references/cases/*.md, which is a file-read capability, but it does not declare any explicit tool scope or allowed-tools restrictions. This creates an authorization gap: the runtime may grant broader file access than the skill actually needs, increasing the risk of unintended local file disclosure if the skill is triggered in the wrong context or later modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill file is written in Chinese and provides no indication that language selection is optional or that the skill is intentionally limited to Chinese-speaking users. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file is entirely written in Chinese and presents the skill content in that language with no indication that users may choose another language or locale. Under the policy rule for natural-language violations, a fixed language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese and presents the skill content in a single fixed language, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructions and guidance exclusively in Chinese, which can constitute a language/locale policy issue when no user opt-in or alternative language option is provided. The content does not indicate that the skill is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file states that quotations are taken verbatim from a path explicitly labeled '资治通鉴_简体', indicating a fixed simplified-Chinese locale choice. Because the content does not offer an alternative language or script option, it can be read as enforcing a locale preference without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.