Back to skill

Security audit

EduClaw - 主动式英语家教

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a tutoring router with no executable tools, but it under-discloses a private paid-subject/contact flow and stores child profile details without clear controls.

Review this carefully before installing. It does not ship executable code or tool access, but parents and users should know that math may trigger an authorization/contact flow, the paid/private upgrade path is not clearly disclosed in the public docs, and the skill may remember child profile details without stated privacy controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
math/agent.yaml:27
Finding

Undisclosed Commercial Redirection Embedded in the Math Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: math/agent.yaml:27-30
Supporting Location: VERSION.md:39-47
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code

math/agent.yaml:27-30 contains instructions that, when translated into English, direct the agent to behave as follows:

yaml
## Initial conversation
When the student says "learn math":
  - If not authorized, suggest trying English first or asking a parent to contact the administrator for more information
  - Administrator account: xiaohuiing123
  - If authorized, begin normal teaching

The associated commercial strategy is documented in VERSION.md:39-47:

markdown
## Business Model

### Current Strategy
- English: Free customer acquisition channel
- Math, Chinese, and other subjects: Intended to become paid offerings

### Monetization Path
- When users request another subject, instruct them to make contact through WeChat and complete the sale privately
- Do not display the price or WeChat details in the public version

Technical Analysis

The math agent's primary instruction block alters its expected educational objective by requiring it to redirect users to an administrator account when an undefined authorization condition is not met. This behavior is loaded as part of the agent's trusted instructions and can therefore override the user's ordinary request to receive math tutoring.

The public-facing documentation presents mathematics as an available subject, while the internal version-management document describes a deliberate strategy of concealing pricing and contact details from the public release and directing users into a private sales interaction. The combination establishes that the redirect is intentional commercial behavior rather than an incidental support message.

The authorization state is not defined in the reviewed configuration, and no trusted application-side ...[truncated 1619 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the administrator account and all private-contact solicitation from the math agent's instruction block.
  2. Keep educational prompts limited to tutoring behavior; do not place sales, authorization, or payment decisions inside model instructions.
  3. If mathematics is a paid feature, disclose that limitation clearly and consistently in README.md, SKILL.md, and the user interface before the user invokes the agent.
  4. Implement entitlement checks in trusted application logic rather than asking the language model to infer authorization.
  5. Define explicit authorization states, deny access deterministically when entitlement is absent, and present a neutral first-party upgrade interface.
  6. Require affirmative parental consent before collecting contact information from or initiating commercial communication involving a child.
  7. Keep payment and support interactions on a documented, monitored organizational channel rather than an individual administrator account.
  8. Add automated tests confirming that subject agents cannot emit undisclosed account identifiers, private-sales instructions, or off-platform contact solicitations.
  9. Reconcile the conflicting version and availability claims across README.md, SKILL.md, and VERSION.md.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README presents the skill entirely in Chinese and instructs users to interact in Chinese without documenting any language choice, fallback, or consent mechanism. This can exclude or mislead users who do not read Chinese, increasing the risk of misunderstanding capabilities, routing behavior, scoring, or data-handling features in a multi-agent educational system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

All user-facing instructions and example invocations are presented only in Chinese, and the skill does not indicate that users may choose another language for interaction. This can violate language/locale policy when a skill implicitly constrains communication to a specific language without offering opt-in or alternatives.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger model is overly broad: users are told to 'just tell me what subject you want to study,' and the system then performs intent recognition and routing. Without explicit activation boundaries or disambiguation rules, unrelated or mixed-purpose inputs could be routed into a skill unexpectedly, causing unintended handling of user data or invocation of the wrong agent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states the public skill is positioned as a free English tutor while privately monetizing broader subject coverage through off-platform WeChat contact. This creates a deceptive identity boundary and encourages users to move to an unreviewed private channel, which weakens platform trust, bypasses oversight, and can expose users to undisclosed commercial or safety risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L66 states '只能用英文标签', while the document otherwise presents Chinese-first operational guidance and does not offer any user or operator language/locale choice. This creates a natural-language locale constraint without opt-in or a clearly documented regional/compliance justification, which matches the policy-violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is labeled as an English-teaching agent, but its system instruction mandates Chinese-language interaction and does not offer the user a language-choice or consent step. This can create a safety and usability issue by preventing comprehension for non-Chinese-speaking users, increasing the risk of misunderstanding instructions, disclosures, or educational content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is entirely defined in Chinese and instructs the agent to interact as a Chinese-speaking elementary math tutor, but it does not offer any language choice or indicate that the skill is intentionally limited to Chinese-speaking users. Under the policy, locale or language constraints should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction to remember student names, preferences, and recurring profile details across interactions creates a natural-language retention path for personal data, especially concerning because the users are children. Without explicit minimization, consent, retention limits, or storage boundaries, the agent may collect and persist more student information than necessary for tutoring.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The first-interaction trigger is the generic phrase "学数学", which is common ordinary user speech and can unintentionally activate onboarding or authorization logic during normal conversation. In this skill, that broad trigger is coupled to access-control messaging and an admin contact, increasing the chance of misrouting users and exposing internal operational details.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The English routing rule uses very broad keywords such as "英语", "english", and especially the nickname-like trigger "小英", which can match user input that is ambiguous or refers to a person rather than a subject. In an LLM-based router, broad triggers increase the chance of unintended agent selection, which can misroute conversations, expose the wrong skill behavior, and degrade any safety or policy boundaries intended per agent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The math rule includes broad keywords like "数学", "math", and particularly "小数", which is highly ambiguous because it is also a common term meaning decimals, not necessarily the agent identity. This can cause unintended routing in normal educational queries and may send users to the wrong agent without clear consent or intent validation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The Chinese-language rule relies on generic keywords such as "语文", "中文", and "小语", which may capture broad language-related conversation rather than an explicit request for this agent. Because the router is configured as type "llm", ambiguous keyword matching can be amplified by model interpretation, increasing misrouting risk and weakening any intended separation between agents.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The documentation states '上下文完全隔离' and that each subject's memory is independent, which is a strong behavioral guarantee. However, the same file describes an intent-recognition router that decides where user input goes, and no code or mechanism is shown here to substantiate 'complete isolation'; this creates an intent-level overclaim in the documentation relative to the apparent design.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.