Back to skill

Security audit

jing-yan-cui-qu

Security checks for vulnerabilities and agentic risk

Overview

The skill is a work-reflection helper, but it tells the agent to automatically persist work-session details that may be sensitive without clear consent, retention, or deletion controls.

Install only if you are comfortable with the agent keeping a local work-history archive. Avoid using it with confidential projects, personnel matters, credentials, or regulated data unless you first add explicit save confirmation, redaction rules, and cleanup/deletion practices.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The global instruction to store all experience data under /memories promotes blanket retention of potentially sensitive user and workplace information. In this skill's context—career reflection, project summaries, decisions, and lessons learned—that repository can accumulate confidential material over time without scoping, filtering, or lifecycle controls.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs automatic persistent logging of conversation-derived work content in plain terms after important sessions. Because this skill is designed to capture work history and reflections, the stored content is likely to include sensitive corporate context, internal decision-making, or personal performance data, increasing the chance of inadvertent disclosure or over-retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs automatic saving of important work-session details, including decisions, challenges, and reusable techniques, into persistent storage without any privacy notice, consent mechanism, retention limit, or data-minimization rule. In a work-reflection context, those records can easily contain confidential business information or personal data, so silent persistence creates a real data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. Under the policy rule for language/locale constraints, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description and operating instructions are presented in Chinese, which can amount to a language/locale constraint if the skill effectively assumes Chinese without user opt-in. Under the policy, language restrictions should either be optional for the user or clearly documented as justified and region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.