Back to skill

Security audit

china-summarizer

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese summarization skill that reads user-provided files or web pages and has no hidden code, persistence, credential use, or automatic destructive behavior.

Install only if you are comfortable letting the agent read the specific files or URLs you ask it to summarize. Avoid using it on sensitive documents from untrusted sources unless you review the output carefully, and install optional tools or Python packages in a controlled environment without unnecessary administrator privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/prompts.md:5
Finding

Indirect Prompt Injection Through Untrusted Source Content

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
references/extract.md:71
Finding

Unpinned Third-Party Dependency Installation Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

text
请安装 PDF 解析工具:
  macOS:   brew install poppler
  Ubuntu:  sudo apt install poppler-utils

提取结果为空或乱码时:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The requirement '用中文输出(无论原文是何语言)' forces a specific language for all outputs. This is a natural-language locale policy issue because it does not provide the user with a language choice or explain a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/extract.md (reported line 66)May include surrounding context.

md
- 速度最快
  安装:
    macOS:  brew install poppler
    Ubuntu: sudo apt install poppler-utils

备选:pypdf(Python)
  - 无需系统工具,纯Python

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt template explicitly requires summaries to be produced in Chinese via the instruction "用中文输出". Under the policy rules, forcing a specific language without offering the user a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file instructs the skill to directly read local text files, which affects user data access. The description does not include any explicit warning or disclosure reminding users that the skill will open and process the contents of local files they reference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, and it does not mention any user opt-in, alternative language, or region-specific justification. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.