Back to skill

Security audit

qualify-requirement-validation

Security checks for vulnerabilities and agentic risk

Overview

This is a China-focused B2B sales qualification playbook with no executable code, hidden data access, persistence, or automatic account changes.

Install this skill for Chinese-language China B2B sales qualification workflows. For non-China prospects, regulated industries, or multilingual teams, treat its China-specific assumptions and public-source suggestions as optional guidance and confirm the customer's region, applicable laws, and privacy expectations before using them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill hard-codes a China-specific operating context, including country-specific organizational assumptions, data-source guidance, and communication norms, without requiring user opt-in or checking whether the customer context is actually Chinese. This can cause the agent to apply inappropriate cultural, regulatory, and sourcing assumptions to non-China users, degrading reliability and potentially leading to misleading business advice or privacy/compliance mistakes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written only in Chinese and does not indicate any option for the user to choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructions, examples, and operational guidance only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file explicitly instructs users to prioritize China-specific regulatory and managerial concerns as a default, which can mislead reps when the customer is not in that jurisdiction or cultural context. This can produce inaccurate discovery, poor recommendations, and privacy/compliance misstatements, especially if users assume the guidance is universally valid.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These prompts mandate China-specific regulatory and business-pressure questions without requiring confirmation that the prospect operates in China or under those laws. If applied out of context, the skill may cause the agent to assert irrelevant legal exposure or culturally mismatched pressure tactics, degrading trust and leading to incorrect qualification decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This file presents all operational guidance exclusively in Chinese and does not indicate that users may choose another language or that the language restriction is justified by a documented regional scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.