Back to skill

Security audit

Identity Primitive Chain

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only task-structuring skill with broad Chinese-language methodology instructions, but no executable code, persistence, credential access, or hidden data movement.

Install this only if you want a Chinese-language task decomposition and role-stacking workflow. Expect it to shape responses with its methodology and to omit some process detail unless requested, but the reviewed artifact does not show code execution, persistence, credential access, or exfiltration behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are very broad and include generic orchestration terms such as identity overlay, task decomposition, execution chain, and meta-skill-system, without defining activation boundaries or exclusions. This can cause the skill to activate in unintended contexts, potentially overriding safer defaults or inserting an opaque reasoning framework into unrelated requests, which increases the risk of prompt-routing abuse and unexpected behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill’s natural-language description and instructions are entirely in Chinese, and there is no statement that users may choose another language or that the Chinese-only scope is intentional for a region-specific use case. This can constitute a language/locale policy issue because the skill appears to impose a language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The exemplar library is entirely in Chinese while the skill metadata does not indicate a Chinese-only contract or require explicit user opt-in. In an agent skill, undocumented language constraints can cause users or downstream agents to misunderstand operating rules, transparency behavior, and execution semantics, which is especially risky here because the skill controls task decomposition, identity stacking, and hidden-vs-shown execution details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The catalog and protocol text are presented entirely in Chinese and describe operation behavior without offering any user language negotiation or fallback. In a general-purpose agent skill, this can cause user misunderstanding of capabilities, hidden execution behavior, and incorrect consent to how tasks are processed, especially when the skill also defaults to concealing internal processing details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill reference is written in Chinese and repeatedly mandates output formats such as reports in Markdown, but it provides no indication that language selection is optional or that Chinese is required for a specific regional or compliance reason. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest and earlier sections state that input/process/output details are hidden by default unless the user asks to see them (L04, L15, L65). However, the facts-discipline rule at L73 says the task-complexity assessment derivation 'must' be shown to the user, which contradicts the default-hidden transparency model for internal execution details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains natural-language instructional content that implicitly fixes the skill output and interaction context to Chinese. Under the policy rule for language or locale constraints, this is a violation because no user opt-in or justification for a Chinese-only locale is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file presents all instructions, examples, and outputs exclusively in Chinese, which can amount to an implicit language requirement. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.