Back to skill

Security audit

geo-cn

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-market GEO marketing workflow skill that stores local client reports, with no evidence of hidden execution, exfiltration, or destructive behavior.

Before installing, be comfortable with a Chinese-language workflow that may create local client archives and reports containing brand, address, phone, platform, competitor, and monitoring data. Keep the geo-clients directory out of shared repos, review reports before sharing, and only publish reports publicly after removing sensitive fields.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file is entirely presented in Chinese, beginning with the title "GEO-CN 更新日志," and contains no indication that other languages are supported or that Chinese is an intentional, documented regional limitation. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation examples are generic natural-language requests such as asking for a GEO diagnosis or asking how a brand performs in AI search. Because these phrases are broad and plausible in ordinary conversation, an agent may activate the skill unintentionally when a user did not explicitly mean to invoke it, causing unexpected workflow execution or steering. In this context the skill is marketing-oriented rather than directly privileged, which lowers severity, but unintended activation remains a real safety issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The embedded HTML template hard-codes lang="zh-CN", which imposes a specific language/locale in a file that otherwise describes a general-purpose skill workflow. The policy allows locale constraints only when they are explicitly justified or user-selectable; here the template does not provide any opt-in or alternative locale handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs persistence of client diagnostic data to local JSON files, including brand, business, region, competitors, and monitoring history, without a clear upfront user warning or explicit consent step. This creates a privacy and data-handling risk because sensitive commercial information may be retained on disk unexpectedly, exposed to other local users/processes, or committed into repos by accident.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The table states the user is responsible for '保存诊断/监测记录文件' while the AI is responsible for '生成并写入记录文件'. Elsewhere, the skill explicitly instructs the AI to create, read, append, and rewrite geo-clients/{品牌名}.json, so the documentation presents conflicting intent about who performs persistent file writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file’s natural-language instructions and usage examples are exclusively in Chinese, with no indication that users may choose another language. This can be a language/locale policy concern because it effectively forces a specific language without documented user opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill tells the agent to prefer the GEO_CLIENTS_DIR environment variable to determine where client records are stored. While this is configuration-related rather than credential access, it still involves environment-derived local path behavior affecting where user data is read/written, and the document does not clearly disclose this behavior as a privacy/storage consideration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.