Back to skill

Security audit

Comprehensive Knowledge System

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable Markdown knowledge and prompt library, but it needs review because it includes broad, under-scoped templates for sensitive advice areas such as medical treatment, finance, law, politics, and security.

Install only if you want a broad Chinese-language prompt and knowledge library, and keep platform safety rules active for medical, legal, financial, political, and security topics. Do not treat its investment, diagnosis, drug, legal, or security templates as professional advice without independent qualified review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/prompts/01-增强提示词套件扩展版.md (reported line 52)May include surrounding context.

md
##### 📊时间序列与对话记录
🚩执行协议等待指令:时间序列分拆成数据方法参数指标场景要素,数据方法参数指标场景要素生成完整分析,默认只展示要素结构但用户可以要求展示完整分析。
🔭执行协议等待指令:​未来预测分拆成数据模型跨度置信目标要素,数据模型跨度置信目标要素生成完整预测,默认只展示要素结构但用户可以要求展示完整预测。
🚨执行协议等待指令:​异常检测分拆成模式算法阈值告警根因要素,模式算法阈值告警根因要素生成完整方案,默认只展示要素结构但用户可以要求展示完整方案。
🔍执行协议等待指令:​序列分解分拆成方法趋势季节残差解释要素,方法趋势季节残差解释要素生成完整分解,默认只展示要素结构但用户可以要求展示完整分解。
👥执行协议等待指令:对话记录分拆成轮次人物内容要素,轮次人物内容要素生成完整记录,默认只展示要素结构但用户可以要求展示完整记录。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/prompts/01-增强提示词套件扩展版.md (reported line 53)May include surrounding context.

md
##### 📊时间序列与对话记录
🚩执行协议等待指令:时间序列分拆成数据方法参数指标场景要素,数据方法参数指标场景要素生成完整分析,默认只展示要素结构但用户可以要求展示完整分析。
🔭执行协议等待指令:​未来预测分拆成数据模型跨度置信目标要素,数据模型跨度置信目标要素生成完整预测,默认只展示要素结构但用户可以要求展示完整预测。
🚨执行协议等待指令:​异常检测分拆成模式算法阈值告警根因要素,模式算法阈值告警根因要素生成完整方案,默认只展示要素结构但用户可以要求展示完整方案。
🔍执行协议等待指令:​序列分解分拆成方法趋势季节残差解释要素,方法趋势季节残差解释要素生成完整分解,默认只展示要素结构但用户可以要求展示完整分解。
👥执行协议等待指令:对话记录分拆成轮次人物内容要素,轮次人物内容要素生成完整记录,默认只展示要素结构但用户可以要求展示完整记录。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/prompts/01-增强提示词套件扩展版.md (reported line 54)May include surrounding context.

md
##### 📊时间序列与对话记录
🚩执行协议等待指令:时间序列分拆成数据方法参数指标场景要素,数据方法参数指标场景要素生成完整分析,默认只展示要素结构但用户可以要求展示完整分析。
🔭执行协议等待指令:​未来预测分拆成数据模型跨度置信目标要素,数据模型跨度置信目标要素生成完整预测,默认只展示要素结构但用户可以要求展示完整预测。
🚨执行协议等待指令:​异常检测分拆成模式算法阈值告警根因要素,模式算法阈值告警根因要素生成完整方案,默认只展示要素结构但用户可以要求展示完整方案。
🔍执行协议等待指令:​序列分解分拆成方法趋势季节残差解释要素,方法趋势季节残差解释要素生成完整分解,默认只展示要素结构但用户可以要求展示完整分解。
👥执行协议等待指令:对话记录分拆成轮次人物内容要素,轮次人物内容要素生成完整记录,默认只展示要素结构但用户可以要求展示完整记录。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language content throughout the file is presented only in Chinese, including the description, usage guidance, and behavior rules. This can amount to a language/locale policy issue because the skill effectively forces a specific language without any user opt-in or documented reason that it must operate only in that locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s activation criteria are very broad and cover common topics like market analysis, prompt writing, creativity, decision-making, and programming workflows. This can cause the skill to activate for many loosely related requests, increasing the chance that its embedded worldview, process instructions, or prompt-engineering conventions influence unrelated interactions without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file describes a behavior that can expose task or project data via share links, including editable links, but does not warn users about the privacy and access implications of creating and distributing such links. Under SQP-2 for markdown files, descriptions that affect user data or privacy should include explicit warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes a sharing feature that lets users choose '通过链接分享' and supports public-link behavior, including configurable expiry and whether public link sharing is allowed. The description does not include any warning that link sharing may expose task contents to anyone with the link or that users should verify permissions and expiry before sharing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt file materially expands the skill from the three declared knowledge domains into broad advisory areas including health, education, finance, security, engineering, politics, and content generation. This creates a scope mismatch that can bypass user and platform expectations, causing the agent to provide high-risk guidance in domains that were not declared, reviewed, or constrained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the model to turn disease symptoms into diagnosis, drugs, and treatment-course outputs, without any warning, limitation, or requirement to defer to qualified medical professionals. In this context, that makes the skill capable of generating unsafe medical-treatment advice directly to users, increasing risk of harm from misdiagnosis, contraindicated drugs, or delayed real care.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Manifest 将该技能描述为涵盖“投资哲学、高级提示词工程、AI编程方法论”三大领域的完整知识库,但该文件实际提供了横跨工程、设计、营销、销售、法务、供应链、游戏、学术等 180 个职业角色的通用提示词模板。这不是实现三大领域知识库的必要细节,而是将技能扩展成了广泛的跨行业职业提示词库,和声明范围存在明显语义偏离。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document contains a very large number of role-specific behaviors covering many domains, all expressed in a uniform 'execute protocol' style but without mutually exclusive triggers or context boundaries. That broad, overlapping surface increases the chance that benign user requests accidentally match a role template, causing unauthorized capability shifts, instruction confusion, or misrouting into sensitive domains like security, finance, legal, or identity-related assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase '执行协议等待指令' establishes a generic activation pattern without explicit trigger conditions, authorization checks, or scoping rules. In a skill system, this can cause prompt collision or unintended role activation from ordinary user input, making the agent follow the wrong behavioral template and potentially bypass higher-level routing or policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill is written as a Chinese-only prompt framework and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt suite uses highly generic invocation language such as '执行协议等待指令' and broad meta-instructions for decomposing and chaining tasks without defining scope, safety boundaries, or allowed use cases. In a reusable agent skill, this can cause the system to apply these powerful behaviors to arbitrary user requests, including sensitive or unsafe contexts, increasing the chance of overreach, prompt misuse, or unsafe task execution patterns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown content forces a specific language/locale for all users and does not indicate that Chinese is optional or that the skill is intended only for a Chinese-speaking audience. Under the policy, language constraints should be user-selectable or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document instructs the workflow to '统一使用Kotlin语言' and describes this stack lock-in as a required constraint. Under the policy for natural-language violations, forcing a specific language without offering user choice or opt-in is a locale/language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description states that the system records access logs for share links, which is a privacy-relevant behavior, but does not warn users that viewer access activity may be logged. For markdown files, omission of privacy-impacting behavior disclosures is in scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file presents operational instructions in specific languages by default, including parallel Chinese and English phrasing, but does not state that the user can choose their preferred language or locale. This can violate a language/locale policy when a skill implicitly imposes preset language behavior without explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This file presents all instructions and content exclusively in Chinese, with no indication that users may choose another language or locale. Under the policy criteria, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.