Back to skill

Security audit

职业技能个性学习路径生成

Security checks for vulnerabilities and agentic risk

Overview

The skill is not overtly malicious, but its bundled scripts and config do not reliably match the promised document-based, official-source learning-path workflow.

Install only if you are comfortable with a draft-quality learning-path tool that may use broader web sources than advertised and may produce template-based outputs. Restrict network access if possible, avoid running demo/test scripts on sensitive systems, and manually verify any generated standards, citations, and quality scores before using them for certification or compliance decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared web scraping of sites like Baidu Baike, combined with handling arbitrary topic queries instead of the provided occupational standard document, materially expands the skill beyond its promised function. This increases the risk of privacy leakage, unbounded content collection, and deceptive outputs that appear to be document-derived when they are not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared web scraping of sites like Baidu Baike, combined with handling arbitrary topic queries instead of the provided occupational standard document, materially expands the skill beyond its promised function. This increases the risk of privacy leakage, unbounded content collection, and deceptive outputs that appear to be document-derived when they are not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared web scraping of sites like Baidu Baike, combined with handling arbitrary topic queries instead of the provided occupational standard document, materially expands the skill beyond its promised function. This increases the risk of privacy leakage, unbounded content collection, and deceptive outputs that appear to be document-derived when they are not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared web scraping of sites like Baidu Baike, combined with handling arbitrary topic queries instead of the provided occupational standard document, materially expands the skill beyond its promised function. This increases the risk of privacy leakage, unbounded content collection, and deceptive outputs that appear to be document-derived when they are not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared web scraping of sites like Baidu Baike, combined with handling arbitrary topic queries instead of the provided occupational standard document, materially expands the skill beyond its promised function. This increases the risk of privacy leakage, unbounded content collection, and deceptive outputs that appear to be document-derived when they are not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared web scraping of sites like Baidu Baike, combined with handling arbitrary topic queries instead of the provided occupational standard document, materially expands the skill beyond its promised function. This increases the risk of privacy leakage, unbounded content collection, and deceptive outputs that appear to be document-derived when they are not.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script advertises generation of a knowledge graph from an input occupational skill standards document, but it never parses or uses such an input and instead emits largely hardcoded structures. This creates a security-relevant integrity issue: downstream users or agents may trust the output as standards-derived and authoritative when it is fabricated or template-based, enabling misleading training content, compliance errors, or unsafe automation decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes producing a three-layer learning path based on an input职业技能标准文档, yet build_occupational_skill_knowledge_graph assembles metadata, domains, nodes, and paths from predefined literals and configuration defaults. There is no parsing or use of any input standard document in this file, so the implemented behavior does not match the advertised document-driven planning capability.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises file and network-related behavior in its workflow, including writing extracted content to /tmp and prioritizing external resource searches, but it does not declare any explicit tool scope or permissions boundary. This creates an authorization ambiguity where users and host systems cannot easily determine or constrain what filesystem and network actions the skill is expected to perform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill targets Chinese domestic vocational skills and uses domestic official resources, and the entire skill content is presented only in Chinese. This imposes a specific language/locale context without indicating user choice or opt-in, which matches the policy category for language or locale constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow explicitly states that extracted PDF text and progress data are written to /tmp files, but it does not warn users that document contents will be persisted locally, even if only temporarily. For standards documents, drafts, or proprietary training materials, this can create confidentiality and retention risks on shared systems or hosts with weak temp-file isolation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 README 从标题到正文均以中文撰写,并在后续示例、字段值与通知模板中默认要求中文输出,没有提供用户可选语言、locale opt-in,或说明该技能仅限中文场景。按规则,未获用户同意而强制单一语言属于自然语言政策风险。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

技能清单描述聚焦于“根据输入的职业技能标准文档,输出基于知识图谱的三层学习路径规划”。但该配置文件整体面向“权威知识图谱构建器”,并定义了资源可用性检查、引用验证、更新策略、缓存并发控制以及插件自动加载等能力,明显超出了单纯生成学习路径所必需的范围。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file's comments and descriptive content are entirely in Chinese, which may indicate the skill is designed around a fixed language context rather than explicitly offering a user language choice. Although supported_languages later includes both zh-CN and en-US, the top-level configuration presentation does not clearly state that language selection is optional or user-driven.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Enabling plugins with automatic loading from a plugin directory introduces code-extension capability that is unnecessary for the stated learning-path task and can expand the attack surface significantly. If an attacker can place or modify files in that directory, the system may load untrusted code or logic, leading to arbitrary behavior, data access, or supply-chain style compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest says the skill should output a three-layer learning path based on input occupational skill standard documents. This extractor introduces an additional capability to query and parse arbitrary Baidu Baike topics from the network, which is not an obvious requirement for processing user-provided standards documents.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a learning-path planner targeting Chinese vocational skill standards and says its reference resources are domestic official resources. This file instead constructs Baidu Baike URLs and fetches encyclopedia pages from baike.baidu.com, which is not an official standards source and represents external content acquisition beyond the stated resource scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a code file, so natural-language policy checks apply to docstrings, comments, and strings. The file title and description mandate Chinese-language interaction by default, and there is no user opt-in, alternative locale, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code claims authoritative resources should be discovered dynamically, but in practice relies on hardcoded default source lists and an unimplemented placeholder collector returning empty results. This can mislead users into believing resources were actually vetted and collected, weakening content integrity and potentially causing false claims of authority in generated learning plans.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing natural-language strings and documentation entirely in Chinese, including the top-level description and many printed status messages. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The _collect_authoritative_resources docstring says the method should search MOOC platforms, national standards, academic databases, and official documentation, and explicitly states resources should be acquired through real search rather than hardcoding. In code, it performs no search at all and returns empty lists, so the documented behavior materially diverges from the implementation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The _calculate_quality_metrics documentation describes computing coverage, coherence, progression, relevance, and reliability from collected resources and graph structure. The function instead returns constant 0.0 placeholders for all metrics, which contradicts the stated calculation behavior in a meaningful way.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring states that the validator is 'domestic-first' and prioritizes domestic open resources, which is a locale/policy choice expressed in natural language. The file does not indicate that users can opt in, opt out, or choose another region/resource policy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Manifest 说明该技能面向中国国内职业技能,且参考资源为国内官方资源;但本文件实际导入并使用 Wikipedia 与 arXiv 作为验证来源,这超出了“国内官方资源”这一描述范围。对于学习路径规划而言,使用外部公共百科和国际论文库并非从 manifest 可直接推导出的实现细节,而是能力边界的扩展。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default configuration forces wikipedia_language to zh, which imposes a specific locale behavior by default. The file does not present this as an optional setting to the user or explain why a Chinese-only locale is required for this skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.