Back to skill

Security audit

wen-xin

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only quality self-check skill with broad, persistent workflow guidance, but no hidden code execution, data access, or destructive behavior.

Install this only if you want a persistent completion-time self-check to influence the agent's responses. Be aware that the optional global-rule instructions can make it run broadly across tools and sessions, and non-Chinese users may need to adapt the wording to their preferred language and output-format expectations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill declares itself mandatory for every task and before any output, giving it global control over agent behavior well beyond a narrow, user-invoked function. This creates prompt-scope hijacking risk: it can interfere with unrelated tasks, override normal response flow, and force hidden preconditions before the agent is allowed to answer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says the answers to the four self-check questions must be naturally reflected in the reply, and the surrounding guidance is entirely in Chinese, with no user-language choice. In a meta-skill that can be forced to run before every completion, this can override user language preferences and cause unintended disclosure of internal process markers in a language the user did not request, degrading usability and instruction fidelity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Describing activation as '按需加载' without precise conditions makes the meta-skill's invocation boundary ambiguous. For a cross-cutting skill that affects final responses, ambiguity can lead to inconsistent triggering, over-application, or accidental bypass, which weakens predictability and may interfere with higher-priority user or system instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The rule 'every time before claiming completion or reporting, must call wen-xin' is extremely broad and overlaps with normal agent behavior in nearly every task. In context, this is more dangerous because the skill is a meta-skill intended for universal use and can be installed as a global rule, so the broad trigger can force pervasive response shaping, create instruction conflicts, and expose internal verification content in places where it is unnecessary or undesirable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill content and description enforce a single Chinese-language workflow without offering user choice, which can reduce usability and transparency for users operating in other languages. In a mandatory meta-skill, this becomes more problematic because it may force responses or validation behavior in a locale the user did not request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include common completion/reporting language like indicating work is done or giving a report, which are routine phrases that appear in many benign conversations. This makes accidental activation likely, causing the skill to insert itself into unrelated interactions and potentially disrupt or gate normal outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.