Back to skill

Security audit

Identity Primitive Chain Prompt

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only skill, but it gives users broad commands to alter the agent's own operating rules and expose internal process details, so it should be reviewed before use.

Install only if you intentionally want a Chinese-language metacognitive prompt framework. Treat requests to modify or unload the protocol, expose internal steps, or make tools/plugins view process data as sensitive actions, and avoid using it where hidden prompts, private inputs, credentials, or confidential intermediate work may be present.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Ssd 1

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The protocol explicitly defines natural-language control hooks such as '卸载协议', '加载协议', '叠加协议', and '修改协议', which allow the governing behavior to be replaced or altered at runtime. In an agent setting, this creates a semantic path for prompt-level privilege escalation or safety bypass, because a user can request removal or mutation of the very rules that constrain behavior.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill includes commands to '展示每个基元的输入处理输出和身份叠加' and to redirect internal process visibility to tools or plugins via '改为工具可以查看' and '改为插件可以查看'. This creates a direct natural-language exfiltration channel for internal reasoning traces, hidden instructions, sensitive intermediate data, or policy-relevant context that should not be exposed to users or external components.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The visible natural-language metadata and instructions are entirely in Chinese, including the core description and execution protocol, with no indication that users may choose another language. This creates a language/locale policy issue because the skill appears to impose a specific language by default rather than offering an explicit opt-in or alternative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document states '使用本提示词时必须按解释B执行', imposing a mandatory language-specific interpretation and execution mode without offering user choice. This can be read as a natural-language policy constraint that forces a particular language/interpretation behavior rather than making it optional or context-justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.