Back to skill

Security audit

通用学习带教模式

Security checks for vulnerabilities and agentic risk

Overview

This is a learning tutor skill that may create study notes and code files, but the behavior is disclosed and limited to its educational purpose.

Use this skill if you want Chinese-language guided tutoring and are comfortable with it creating study files in your workspace. Before long sessions, tell the agent which directory to use and to ask before overwriting existing files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and core instructional description are presented exclusively in Chinese, indicating the skill is intended to operate in a specific language. The file does not offer an opt-in language choice or explain why the language restriction is necessary, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata promises automatic code and document generation but does not disclose that it may create or modify files in the user's workspace. In an agent environment, undisclosed write behavior can surprise users, overwrite existing work, or cause unintended persistence of generated content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The algorithm workflow instructs the agent to update progress.md and generate solution and documentation files automatically, but it provides no user-facing notice or approval step. This is risky because the agent could alter the repository state or overwrite files during normal tutoring interactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Python mode similarly directs automatic updates to progress documents and creation of exercise code and notes without warning the user that workspace files will be changed. Even in a benign educational skill, silent file writes can lead to unwanted modifications, clutter, or accidental overwrites.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.