Back to skill

Security audit

洞明

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language strategy analysis skill with disclosed report-writing, self-critique, and optional expert-routing behavior, and I found no executable code, persistence, credential handling, or exfiltration behavior.

Install this if you want a Chinese-language strategic analysis workflow. Be aware that it may route complex questions to expert subskills and tends to prioritize China-market examples/data; for sensitive business strategy, specify the market, language, confidentiality expectations, and whether expert delegation is allowed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises implicit activation for broadly defined 'strategic decision intent', which can cause the agent to invoke this skill in many ambiguous conversations that merely resemble planning or analysis. Overbroad routing increases the chance of unintended context capture, inappropriate authority escalation for a 'chief-agent' role, and misapplication of the skill outside the user's actual request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains natural-language guidance exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and the entire specification are written as a prescriptive output standard in Chinese, and no section indicates that language selection is optional or user-driven. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file is entirely written in Chinese and provides mandatory operational instructions without offering a language fallback or documenting that the skill is intentionally restricted to Chinese-speaking users. This can cause users or supervising systems to miss critical review steps, misinterpret constraints, or receive outputs in an unexpected language, which is especially problematic in a strategy-analysis skill where correctness and reviewability matter.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The protocol states that at most two experts may be invoked at once, but later says S-level problems should use two core experts plus one on-demand expert. This contradiction can cause unpredictable orchestration behavior, bypass intended resource limits, and produce inconsistent analysis paths depending on which instruction an agent follows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation thresholds ('simple', 'medium complexity', 'complex', 'S-level') are underspecified and subjective, so an agent can over- or under-invoke experts without clear guardrails. In a strategy skill, this creates reliability and control risks: excessive delegation may leak more context than necessary, while insufficient delegation may lead to unsupported conclusions presented as rigorous analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains end-user instructional content exclusively in Chinese, and nowhere indicates that users may choose another language or that the skill is intended only for Chinese-speaking contexts. Under the policy rule for language/locale constraints, forcing a single language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire reference document is written in Chinese and does not indicate any language choice, opt-in, or region-specific justification. Under the policy, natural-language content that imposes a specific language without user choice can be considered a locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The output requirement states that Chinese market real data should be prioritized, which imposes a locale-specific preference in the skill's instructions. The file does not indicate that this is optional, user-selected, or limited to a clearly documented region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.