Back to skill

Security audit

家校沟通话术台

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language education writing aid for teacher-parent communication, with no executable code, external access, persistence, or hidden behavior found.

Before installing, expect this skill to help draft Chinese teacher-parent communication scripts. Avoid entering unnecessary identifying student or parent details, and manually review outputs for sensitive, legal, medical, safety, or psychological-crisis situations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keywords are broad, generic phrases like '家校沟通', '家长会', and '通知家长' that can appear in many ordinary educational conversations. This increases the chance of unintended activation, causing the wrong skill to respond and potentially exposing user-provided student or parent information to an unnecessary workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

All user-facing description, examples, and trigger phrases are presented exclusively in Chinese, and the file does not indicate that the user can opt into another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.