Back to skill

Security audit

Mao Emperors

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language decision-support roleplay skill with no executable code or hidden system access, though it uses strong political and historical rhetoric that users should treat carefully.

Install only if you intentionally want a Chinese-language, Mao-and-emperor-themed roleplay framework for brainstorming decisions. Treat its ideological and punitive language as stylistic/historical framing, not as operational advice for real-world coercion, violence, retaliation, or workplace discipline.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This markdown file presents all user-facing content in a single language, and there is no indication that users can opt into another locale or that the skill is intentionally limited to a Chinese-only audience. Under the policy rule for natural-language locale constraints, forcing one language without opt-in is a reportable issue.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file is fully written in Chinese and provides no indication that users may choose another language or that the language restriction is justified, which can amount to forcing a specific language without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
This markdown file appears to require Chinese for all user-facing guidance, and it does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The README title and the entire usage documentation are presented in Chinese, and the listed trigger phrases and examples are all Chinese-language invocations. There is no indication that users may interact in other languages or choose a preferred locale, which can violate language/locale policy when a skill effectively forces a specific language without opt-in.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill is written entirely in Chinese and presents examples, structure, and interaction framing only in Chinese without offering a language-selection mechanism or documenting a justified locale constraint. This can exclude or mislead users who operate in other languages, causing incorrect use, reduced accessibility, and higher risk of misunderstanding in decision-support contexts.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill is written entirely in Chinese and strongly constrains the agent to a Chinese-speaking historical persona without indicating whether other user languages are supported. This can cause accessibility, usability, and policy-compliance issues by preventing users from receiving responses in their preferred language and by making the agent's behavior less transparent across locales.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill is written entirely in Chinese and defines example outputs and interaction style in Chinese without offering an alternative language path or documenting a legitimate locale restriction. In a multi-agent or user-facing environment, this can exclude users, cause misunderstandings of instructions or safety constraints, and reduce operator visibility into the agent's behavior.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill is entirely written in Chinese and presents a Chinese-language persona without any indication that language should adapt to the user's preference. This can cause the agent to respond in a language or locale the user did not request, reducing usability and potentially causing misunderstandings in security- or policy-sensitive interactions.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown skill specifies identity, style, and example outputs solely in Chinese, which can effectively force a specific language on users. The policy allows language constraints only when users are given a choice or when the restriction is clearly documented and justified, neither of which appears here.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly frames itself around armed struggle, class enemies, and mass mobilization without any safety boundaries, de-escalation guidance, or restriction to historical/fictional discussion. In a live agent setting, this can normalize or operationalize violent political rhetoric and could be repurposed to generate harmful advocacy or intimidation content.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The description and all listed triggers are Chinese-centric and do not provide any language choice, fallback behavior, or explicit locale restriction. In multilingual environments, this can misroute users or silently force interaction in a language they did not choose, reducing transparency and increasing the chance of misunderstanding or unsafe advice application.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains generic phrases such as strategic analysis, contradiction analysis, and organizational design that can plausibly appear in ordinary user conversation. This can cause unintended activation of the skill, leading to response hijacking, user confusion, and routing of unrelated prompts into this skill without clear user intent.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
All visible instructions, persona definitions, and example outputs are written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language context. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern.

Static analysis

No suspicious patterns detected.