Back to skill

Security audit

success-expansion

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed China-focused sales expansion playbook with no code execution, persistence, or hidden data access.

Install this if you want a China-market B2B expansion and upsell playbook. Before using it with real customers, confirm the account region, communication preferences, procurement rules, and privacy/compliance limits, especially before using WeChat, screenshots, customer statements, or tendering signals as evidence.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill hard-codes China-specific signal sources, operating assumptions, and go-to-market practices without requiring the user to confirm region or account context. This can cause the agent to generate misleading or inappropriate business guidance for non-China customers, leading to poor decisions, compliance mismatches, or privacy/process issues when it suggests region-specific data sources and sales motions by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed communication strategy assumes China-specific norms such as WeChat/企微 messaging, decision-maker formats, and social interactions, but does not offer locale alternatives or ask for user preference. In the wrong context, this can push the agent to recommend culturally inappropriate or potentially noncompliant outreach behavior, reducing trust and creating operational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all instructions and guidance exclusively in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a China-specific audience. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill hard-codes a China-specific communication style and instructs the agent to use specific conversation starters and messaging norms without any user opt-in or applicability check. This can cause the agent to inappropriately localize output, make unsupported assumptions about the customer's region and business culture, and generate communications that are mismatched, biased, or non-compliant for other audiences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section labeled '中国沟通形态' mandates China-specific channels and behaviors such as WeChat group messaging, Moments interaction, and dinner/face-to-face talking points, without documenting when these tactics are appropriate. If applied outside the intended context, the agent may produce culturally inappropriate or privacy-sensitive outreach strategies and steer users toward region-specific practices they did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is written entirely in Chinese and is explicitly tailored to China-specific signal sources and workflows, including WeChat, Chinese procurement platforms, and '中国信号源'. This imposes a specific language and locale context without any opt-in or indication that the skill is region-specific by design for users who may need another language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is written as a prescriptive template centered on Chinese-language fields and explicitly China-specific procurement, stakeholder, and tendering workflows. Because it does not present this locale as optional or limited to a region-specific variant, it effectively imposes a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill file is written in Chinese, including headings, scoring guidance, and action instructions, with no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy rule, a skill that effectively requires a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.