Back to skill

Security audit

ParentCN 全龄段育儿助手

Security checks for vulnerabilities and agentic risk

Overview

This coherent parenting skill should go to Review because it gives actionable child health, feeding, vaccine, medication, and first-aid guidance without adequate medical safety boundaries.

Install only if you want a Chinese parenting content reference and will treat its medical, vaccine, feeding, medication, allergy, and first-aid material as draft educational content. Users should verify health claims against current local pediatric or public-health guidance before relying on or publishing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

High
Confidence
97% confidence
Finding
This skill provides vaccine schedules, home care guidance for fever/diarrhea/eczema, medication examples, and choking first-aid instructions, but it lacks prominent disclaimers, emergency escalation criteria, and a strong boundary that it is not a substitute for professional medical care. In a parenting context, users may rely on this guidance for infants and children, so omissions or oversimplified advice can delay urgent care or lead to harmful self-treatment.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The content-creation trigger is underspecified because it activates for public-account or Xiaohongshu parenting content generation without defining boundaries on acceptable topics. This can unintentionally pull the skill into producing authoritative-sounding childcare or medical-adjacent content even when the request is vague, promotional, or outside safe scope.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
L003 和标题内容均以中文固定描述技能用途,但未说明是否支持其他语言,也未给用户提供语言选择或明确的中文限定理由。按照语言/locale 政策,若技能默认强制单一语言而无用户选择,可能构成自然语言策略问题。

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The file contains pediatric feeding, sleep, and vaccination templates that present health-related guidance in a confident, instructional style without advising users to consult pediatricians or account for individual medical history, allergies, developmental differences, or contraindications. In a parenting skill, users are likely to rely on this content as actionable advice, which raises the risk of harm from outdated, overgeneralized, or medically inappropriate recommendations.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The guide states '可加少量盐或不加' in the 8-9 month section, which is unsafe because infants under 12 months should generally avoid added salt due to immature kidneys and sodium burden. In a parenting skill, caregivers may treat this as actionable feeding advice and introduce salt earlier than recommended, creating avoidable health risk and normalizing incorrect infant feeding practices.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The severe allergy advice says to seek care immediately, but for symptoms like breathing difficulty and lip swelling, the guidance should clearly signal a medical emergency requiring emergency services/ER care rather than ordinary monitoring. In a childcare context, ambiguous wording can delay urgent response during anaphylaxis, where minutes matter and harm can escalate rapidly.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This file provides detailed vaccine schedules, recommendations, contraindication-adjacent advice, and post-vaccination management in a medical domain without clearly directing users to confirm advice with licensed clinicians or the current local immunization program. Because vaccine schedules vary by country, province, product type, and year, outdated or overgeneralized guidance could lead to missed, delayed, duplicated, or inappropriate vaccinations, and the parenting skill context makes users likely to act directly on the content.

Vague Triggers

Low
Confidence
88% confidence
Finding
The content-creation trigger is underspecified because it activates for public-account or Xiaohongshu parenting content generation without defining boundaries on acceptable topics. This can unintentionally pull the skill into producing authoritative-sounding childcare or medical-adjacent content even when the request is vague, promotional, or outside safe scope.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
Natural-language policy review applies to all file types, including markdown. The file presents all instructions and templates exclusively in Chinese, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-language audience for a documented reason.

Static analysis

No suspicious patterns detected.