Back to skill

Security audit

Diting Employee Development Expert

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only HR advisory skill that does not run code, but it should be used carefully with sensitive employee information.

Install only for authorized HR or management use. Avoid feeding unnecessary personal identifiers, salary details, or legally sensitive facts into the skill, and route compensation design, pay-equity, termination, or labor-law questions to qualified HR/legal workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The manifest description is written as an instruction set for when to use the skill, but it is entirely Chinese and does not indicate that other languages are supported or that Chinese is required for a specific regulated or regional context. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The substantive skill instructions, scenarios, and outputs are all authored in Chinese, and there is no statement offering multilingual support or requiring the dispatcher to respect the user's preferred language. This can amount to a language-policy violation because the skill implicitly constrains responses to a single language.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The manifest explicitly states the skill is not suitable for compensation structure topics, yet the retention scenario instructs use of '薪酬对标' as a long-term intervention. That extends behavior into compensation-related guidance beyond the declared employee-development-only scope.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The template encourages outputs about specific employees, talent-loss risk, successors, and intervention actions without any warning to minimize personal data, avoid unnecessary identifiers, or obtain proper authorization. In an HR setting this materially increases the chance of exposing sensitive personnel assessments and producing high-stakes recommendations tied to identifiable individuals.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill metadata explicitly says it is not suitable for compensation structure, labor-law compliance, or other non-employee-development topics, yet this template adds a "talent attrition warning and retention" scenario that expands the skill into attrition analytics and personnel intervention. In an HR context, this can lead the agent to provide unsupported retention-risk judgments and employee-specific actions that affect employment decisions beyond the declared scope.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The template instructs the model to analyze resignation causes including "薪酬不公" (pay inequity), which directly conflicts with the skill's stated boundary excluding compensation-related topics. This mismatch can cause the agent to generate sensitive compensation inferences or quasi-legal/HR conclusions without the required expertise, governance, or disclaimers.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
This markdown file presents all headings, instructions, and templates exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in or a documented justification can be a natural-language policy violation.

Description-Behavior Mismatch

Low
Confidence
76% confidence
Finding
The manifest says the skill is not for training needs analysis or course design, but the documented behavior includes creating structured development plans under the 70-20-10 framework and IDP templates. While not full course design, this partially overlaps with training-planning activity and weakens the stated boundary.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all instructional content in Chinese and does not indicate that the user can choose another language or that the locale restriction is required for a region-specific purpose.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
The title and instructions are presented only in Chinese, and all output templates are defined in Chinese without indicating that users may choose another language. SQP-3 applies to all file types and flags language policy issues when a skill appears to force a specific language without user opt-in or documented justification.

Static analysis

No suspicious patterns detected.