Back to skill

Security audit

Internship Review

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language internship reflection template skill with no executable code, but users should share only curated internship notes and confirm any file write path.

Install at project scope when possible. Before sharing notes, redact employer-confidential information, third-party personal data, credentials, and unrelated diary entries. Ask the agent to show the generated markdown inline first and confirm the exact save path before it writes or overwrites a file.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and usage content are fully Chinese, and the file does not state that the skill is China-specific or provide any user language opt-in. This can amount to forcing a specific language/locale without explicit choice, which matches the language-policy concern described in the rule.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README lists activation phrases such as "帮我复盘实习" and "写一份实习回顾" without any negative examples, boundary conditions, or platform-specific constraints. These are natural conversational requests that could overlap with ordinary chat, making it unclear when the skill should activate versus when the agent should respond normally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README says that saying "帮我复盘实习" will start the skill, but it does not explain how this differs from an ordinary request for help with internship reflection. Without clear trigger scope or opt-in boundaries, the invocation condition is underspecified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest lists several specific trigger phrases, but then expands scope to "any request to turn internship experience into a structured review document," which is ambiguous and broad. Without clearer boundaries or exclusion examples, this could cause unintended invocation for ordinary reflection or writing-help requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill tells the agent to proactively request access to internship-related notes and diaries, which are likely to contain sensitive personal or employer information, without a privacy warning or data-minimization guidance. In context, this is more dangerous because the requested materials are described as the richest source, encouraging broad collection of potentially confidential data that may exceed what is necessary for drafting a review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to write generated content into user storage locations such as an Obsidian vault or local files without requiring an explicit confirmation step or warning about file modification. This creates a risk of unintended file creation or overwriting, especially if the agent infers a destination or acts before the user understands that a persistent change will occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly tells the agent to ask for users' notes or journals and to write generated markdown to a user-specified location, but it provides no warning about sensitive personal data, no minimization guidance, and no confirmation step before writing. In a workflow centered on reflective internship materials, those notes may contain private details about the user, coworkers, or employers, so unrestricted collection and file-writing can cause unnecessary exposure or accidental overwrite.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill proactively encourages ingestion of personal journals or note-system content as the 'best' source material, which increases the chance that highly sensitive personal, academic, or workplace information will be exposed to the agent unnecessarily. Because internship diaries often include candid reflections, internal company details, and identifiable information, this instruction promotes over-collection beyond what is needed to help structure a review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language instructions, examples, and user-facing prompts are all in Chinese, which implies the skill is designed to respond in a specific language. There is no stated user opt-in, language selection mechanism, or documented reason for restricting the skill to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for language or locale constraints, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown template is entirely written in Chinese and provides instructions only in that language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.