Back to skill

Security audit

Diting Training Expert

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent training-advisory skill with no executable behavior, though its HR templates should be used with privacy care.

Installers should treat this as a Chinese-first training advisory skill. Before using its questionnaires or evaluation forms with employees, add consent, minimization, access-control, retention, and confidentiality language, and avoid reusing training feedback as performance or disciplinary evidence without proper policy notice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The manifest description is written as an instruction for use in Chinese and does not indicate that other languages are supported or that the user can choose the response language. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The operational instructions are entirely specified in Chinese and define the skill's expected interaction behavior without mentioning multilingual support or user language preference. This creates an implicit forced-language policy issue because the skill's working mode is constrained to one language with no opt-in or alternative path.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The document title and guidance specify output templates entirely in Chinese and instruct users to reference this file for output documents, which implies a fixed language requirement. There is no indication that users may choose another language or that the Chinese-only constraint is required for a region-specific or compliance reason.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The questionnaire template directly solicits identifiable employee data such as name, department, role, and level, along with training needs and workplace challenges, but provides no guidance on consent, minimization, access controls, retention, or appropriate use. In an HR/training context this can lead to unnecessary collection and misuse of employee profile data or sensitive self-assessments, especially if reused for evaluation beyond training planning.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The evaluation template captures supervisor assessments, learner behavior observations, support needs, and business-performance metrics, but lacks any confidentiality, role-based access, or misuse warning. Because this is embedded in a training skill, users may treat it as a ready-to-deploy form and collect performance and managerial evaluation data that could affect employees without notice, safeguards, or separation from formal HR decisions.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
This markdown file contains user-facing instructional content exclusively in Chinese, starting from the title and continuing throughout the document. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Static analysis

No suspicious patterns detected.