Back to skill

Security audit

Personal Office Aasistant

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Chinese office-assistant writing skill with no code, network use, persistence, or hidden privileged behavior.

Install this if you want a Chinese-language helper for office writing and document organization. Review outputs before using them for legal, financial, contract, performance, or external communications, and be aware that short Chinese requests like asking to write, polish, or organize text may invoke the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content is entirely in Chinese and sets behavioral expectations in Chinese without offering language negotiation or honoring the user's preferred language. This can lead to user confusion, misinterpretation of instructions, and unsafe workflow errors if the user expects another language, especially in business contexts involving approvals, contracts, or external communications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples map very short, everyday phrases like '帮我写一下', '润色一下', and '整理一下' to automatic office-task behaviors. This can cause the skill to activate in contexts where the user did not explicitly intend to invoke this specific skill, increasing the risk of prompt-routing mistakes, unwanted processing of unrelated content, or accidental handling of sensitive workplace text.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill is described as a broad 'general assistant' for personal office scenarios, without strong limits on when it should or should not apply. Overly generic scoping can cause unintended activation overlap with many normal productivity requests, which weakens routing precision and may expose user content to the wrong skill context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.