Back to skill

Security audit

学习助手(免费版)

Security checks for vulnerabilities and agentic risk

Overview

This learning skill is not clearly malicious, but it asks for read and command-execution access while advertising broad automation, file, API, and task-management behavior beyond a learning assistant.

Review before installing. Use this only if you are comfortable giving a learning-plan helper command execution and local read capability, and prefer a revised version that removes exec, narrows activation to education-only prompts, and clearly states whether any external APIs or credentials are used.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest describes a learning assistant, but the description also invites use for project management, task planning, progress tracking, and team collaboration. This scope expansion can cause the agent to invoke the skill in contexts unrelated to learning, increasing the chance that its declared read/exec abilities are used more broadly than users expect.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The documentation advertises generic create/query/export/modify/delete operations instead of clearly bounded learning-plan and exercise-generation behavior. Broad operational claims make the skill appear like a general-purpose automation wrapper, which can justify risky tool use beyond the manifest's intended educational scope.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill claims file processing, external API integration, command execution, and information retrieval capabilities that materially exceed a learning assistant's stated purpose. This creates a deceptive mismatch where a seemingly harmless educational skill may be invoked with powerful behaviors that can access local data or execute commands.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Granting exec to a learning-plan assistant is unjustified by the stated functionality and significantly increases attack surface. Any ambiguous or adversarial prompt routed to this skill could lead the agent to run shell commands for a task that should be solvable with pure text generation.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Documenting external API calls for a Markdown-based learning assistant introduces unnecessary outbound communication paths without a clear product need. This can expose prompts or user data to third parties and expands the opportunity for data exfiltration or unsafe dependency on remote services.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill says no extra API key is needed, yet later discusses API keys in environment variables and external service usage. These contradictions can mislead operators about whether secrets are required or may be accessed, weakening trust and making unsafe deployments more likely.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation description is overly broad and invites invocation for non-learning scenarios such as team collaboration and project/task management. In context, this is dangerous because the skill also exposes read/exec capabilities, so ambiguous routing can cause a powerful skill to activate outside its legitimate domain.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The invocation guidance provides generic scenario descriptions but lacks strict trigger conditions and operational constraints. When combined with broad capability claims and exec access, this ambiguity raises the risk of accidental or policy-bypassing use in unrelated workflows.

Static analysis

No suspicious patterns detected.