Back to skill

Security audit

success-business-review

Security checks for vulnerabilities and agentic risk

Overview

This is a China-market customer-success review playbook with no executable code, network behavior, persistence, or hidden authority, though users should handle customer screenshots and complaint data carefully.

Install this only for China-market customer-success review workflows. Before using customer screenshots, complaint tickets, or internal account notes, redact unnecessary personal or confidential details, keep internal briefs separate from customer materials, and require human review before anything is sent externally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill hard-codes China-specific decision hierarchies, communication norms, and evidence formats as default operating instructions without asking whether the customer, account team, or locale actually matches that context. This can cause the agent to produce culturally mismatched or inappropriately localized business content, creating trust, compliance, and suitability risks when used outside the intended China-market scenario.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to prefer Chinese business phrasing and deemphasize other framing steers outputs toward one cultural communication style without user opt-in. If applied to the wrong audience, it can distort messaging, reduce effectiveness, or create reputational and relationship harm by presenting assumptions about executive preferences as universally valid.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

These lines prescribe WeChat/enterprise WeChat reporting, formal meetings, and reject async/digital QBR as required practice for Chinese customers. This is a natural-language locale/policy constraint that forces a specific regional communication pattern without offering an alternative or stating that it applies only when the customer explicitly prefers it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file hard-codes a China-specific communication model ('中国含蓄化改造') and instructs users to avoid direct asks in favor of culturally tailored post-meeting follow-up, without requiring user opt-in or clearly scoping the skill to that locale at execution time. This can cause the agent to apply region-specific business norms to the wrong customer context, leading to inappropriate guidance, degraded outcomes, and potentially discriminatory or biased behavior in cross-cultural settings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document explicitly recommends using complaint tickets and WeChat complaint screenshots as internal evidence without any warning about privacy, minimization, access control, retention, or consent. Even though it says this content should stay internal, this workflow handles sensitive customer communications and creates risk of unnecessary collection, over-sharing, and downstream leakage of personal or confidential information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains natural-language instructions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the language/locale policy rule, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing operational guidance only in Chinese, and nowhere indicates that Chinese is optional or that the skill is restricted to Chinese-speaking users. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L03 states this is a '中国改造' workflow, and the rest of the document consistently mandates China-specific practices rather than presenting them as optional. Because the skill content is written as required operating guidance and does not offer opt-in or alternative locale handling, it constitutes a language/locale policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.