Back to skill

Security audit

conjecture-prover

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese-language conjecture analysis aid with RH example materials and an optional local verification script, with no hidden persistence, credential access, network access, or install-time execution found.

Install this only if you want a Chinese-language proof-planning and conjecture-reduction workflow. Treat its RH materials and generated outputs as research scaffolding, not authoritative proofs, and independently verify any mathematical, scientific, or historical claims before relying on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The description presents a generalized meta-skill for proving or reducing conjectures across many fields. The supplied code does not implement such a system. Instead, it is a single-purpose numerical verification script for one mathematical claim related to the Riemann Hypothesis. It computes ξ-function values, finite-difference derivatives, convexity checks, and comparisons against a zero-sum formula using hard-coded sample grids and known zeros. While this is loosely within the umbrella of 'conjecture/proof' work, the actual implemented behavior is far narrower and materially different from the declared broad, domain-spanning proof pipeline. No evidence appears of arbitrary-domain support, task generalization, decomposition machinery, reduction framework, or the advertised meta-skill system.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very broad terms such as '猜想', '证明', and '归约', which are common in normal academic or analytical conversation. That can cause unintended invocation of this skill in unrelated contexts, leading the agent to enter an overconfident proof-generation workflow, produce misleading outputs, or bypass better-suited domain behaviors.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The natural-language instructions and description are presented entirely in Chinese, and the skill does not state that users may choose another language or locale. This creates a language policy concern because the skill appears to impose a specific language without explicit opt-in or documented justification.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file title and all instructional content are presented exclusively in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-only audience. Under the stated policy, forcing a specific language without user opt-in is a locale-policy violation.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This file contains user-visible natural-language text entirely in Chinese, including the title, description, and labels. Under the language/locale policy rule, forcing a specific language without opt-in or documented justification is a policy concern, and no such choice or justification appears in the file.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file contains natural-language instructions and descriptions exclusively in Chinese, but nowhere indicates that the skill is Chinese-only or gives users an option to select another language. Under the language/locale policy rule, forcing a specific language without user opt-in is a policy concern.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file is natural-language skill guidance, and its title and subsequent instructions are presented exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in is a locale-policy issue unless the document clearly justifies a region-specific constraint or offers alternatives, which this file does not.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The module docstring and runtime instructions are written in Chinese, and the script's user-facing output is also presented exclusively in Chinese. This imposes a specific language on users without opt-in, which matches the language/locale policy violation criteria.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
All printed headings, verification summaries, and conclusions are in Chinese, so any user running the script must consume the results in that language. There is no opt-in, fallback, or locale selection mechanism, so this is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This markdown file contains natural-language instructions/content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Per the policy, forcing a specific language without user choice is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
This markdown file presents all user-facing content exclusively in Chinese, beginning with the title and continuing through the full review report. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
The file title and core content are primarily written in Chinese, with only a secondary English subtitle, and there is no statement that users may choose another language or that the locale restriction is required. Under the policy for natural-language violations, forcing a specific language without opt-in can be a violation.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
The document title and all user-facing content are written in Chinese, and the file does not indicate any language selection, alternative locale, or user opt-in. Under the stated policy, forcing a specific language without choice can be a natural-language policy violation unless clearly justified as region-specific.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This SVG contains all user-visible labels and descriptions in Chinese, including the title, description, and diagram annotations. For a general-purpose skill asset, this is a natural-language locale constraint with no visible opt-in, alternative language, or justification that the asset is intended only for a Chinese-language context.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
The SVG's human-readable title, description, and labels are entirely in Chinese, which is a natural-language locale choice embedded in the file. Under the stated policy, forcing a specific language without opt-in or documented justification can be a policy violation.

Natural-Language Policy Violations

Low
Confidence
97% confidence
Finding
This markdown file is entirely presented in Chinese, and there is no natural-language indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without opt-in is a language/locale policy concern.

Static analysis

No suspicious patterns detected.