Back to skill

Security audit

商业模式学习智能体

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language business-model learning aid with no evidence of hidden access, persistence, credential handling, network use, or destructive behavior.

Install this if you want Chinese-language help with business-model canvases, case studies, and innovation frameworks. Be aware that broad terms like business model, profit model, and monetization may trigger it in general business conversations, and non-Chinese users may need to ask explicitly for another language.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad, common business terms such as '商业模式', '盈利模式', and '变现', which can easily appear in ordinary conversations and unintentionally activate the skill outside clearly scoped requests. This increases the chance of over-triggering, causing the agent to respond with this skill in contexts where it is not the best match and potentially overriding user intent or routing decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill metadata and instructions are entirely in Chinese and do not state whether output language should follow the user's preference, which can cause forced language behavior in multilingual environments. While not directly enabling code execution or data exfiltration, this can degrade usability, cause misinterpretation of analytical advice, and lead to unsafe misunderstandings if users cannot accurately assess the output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

For markdown files, natural-language policy violations include forcing a specific language without user opt-in. This guide presents all instructions and content in Chinese only, and there is no indication that the skill is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is entirely presented in Chinese starting from the title and introductory description, with no indication that the language is optional or that the skill is specifically limited to Chinese-speaking users. Under the policy, a fixed language or locale without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and generated output are explicitly in Chinese, and the functions always produce Chinese-language Markdown content. This is a natural-language locale constraint with no user opt-in or documented justification, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructional content exclusively in Chinese and does not indicate that the user can choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.