Back to skill

Security audit

Content Compliance Review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed content-compliance reviewer for mainland China social platforms, with local reference files and a simple rule validator that fit its stated purpose.

Install this only if you want a mainland China platform compliance-review helper. Review sensitive drafts carefully before sending them to any agent or model service, redact credentials and private personal data, and verify current official rules for high-stakes or time-sensitive publication decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a user-facing social-media compliance reviewer, but its documented behavior includes reading and maintaining internal rule files and running a local validation script. That mismatch can cause the agent to access local repository content or perform maintenance actions when the user only expected content review, violating least surprise and potentially exposing internal files or enabling unintended internal operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README presents the skill entirely in Chinese and states it is for creators in Mainland China, which imposes a specific language/locale context by default. Under the policy, locale constraints should either be user-selectable or clearly documented as a justified region-specific tool.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 76)May include surrounding context.

Claude Code

bash
mkdir -p "$HOME/.claude/skills"
git clone https://github.com/xiaoxiaochen5678-dot/content-compliance-review-skill.git \
  "$HOME/.claude/skills/content-compliance-review"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file presents the platform name and the entire rule summary in Chinese, but does not state that the skill is intentionally Chinese-only or offer any language/locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description says to use the skill when a user asks for "content compliance review, pre-publication risk checking, platform rule comparison, moderation-risk diagnosis, or safer revisions" without defining specific trigger phrases or exclusion conditions. Several of these phrases are broad enough to match ordinary editing or strategy requests, which could cause unintended activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill presents itself in Chinese in the display name and description, but the default prompt text is fixed in English. This creates a language-policy concern because the file hardcodes a language choice without indicating user opt-in or offering an alternative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains user-facing policy content exclusively in Chinese, and it does not state that the skill is limited to Chinese-speaking users or provide any language/locale opt-in. Under the policy-violation category, forcing a specific language without user choice can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This reference file presents the platform name and heading entirely in Chinese and identifies the jurisdiction as mainland China, but it does not state that the language choice is region-specific or optional for users. Under the policy rule for language or locale constraints, forcing a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L50 instructs reviewers to mark findings with 待核实, which imposes a specific non-English label in otherwise English schema guidance. This is a natural-language locale choice without any stated user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.