Back to skill

Security audit

雄韬易经 - 做生意好帮手

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese business-analysis skill with local reference reads and optional HTML report generation; the main cautions are broad trigger wording, file output, and fixed XTOCN branding.

Install only if you want a Chinese-language I Ching-style business analysis framework. Review generated HTML reports before sharing because they may contain sensitive business details and fixed XTOCN branding, and treat personnel, discipline, legal, or financial recommendations as strategic reflection rather than final advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
references/frameworks/report-template.html:219
Finding

Hardcoded Third-Party Branding in Generated Reports

Content
View full analysis
易经商业决策模型 · 雄韬XTOCN · www.xtocn.com
本报告由 AI 基于易经思维模型框架生成,仅供参考,不构成决策建议。
``` The footer states that the report uses the XTOCN I Ching business decision model, includes the `www.xtocn.com` domain, and presents a disclaimer that the AI-generated report is for reference only and does not constitute decision advice. ### Technical Analysis The report-generation workflow directs the agent to load `references/frameworks/report-template.html`, substitute analysis content into its placeholders, and write the resulting document as an HTML file. The template contains a fixed footer promoting XTOCN and its domain. Because the footer is unconditional and the workflow provides no documented mechanism to remove or disable it, every report produced through this path carries third-party promotional content. This modifies the agent's final deliverable beyond the business analysis requested by the user and turns generated reports into a distribution channel for the third-party brand. This is classified as instruction hijacking because skill-level instructions control the content of the agent's output. It does not execute code, contact the domain automatically, or alter the agent's general safety controls. ### Attack Path 1. A user invokes the skill and requests a complete report or PDF-ready output. 2. The skill instructs the agent to read `references/frameworks/report-template.html`. 3. The agent fills the template placeholders with the user's question and generated analysis. 4. The fixed footer remains in the generated HTML because it is not represented by an optional placeholder. 5. The user opens, shares, or prints the report as a PDF. 6. The resulting deliverable distributes ...[truncated 855 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (35)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description lists expansive situations such as '商业决策困惑' and '组织管理' without clear boundaries, then says the user can start the skill with '/雄韬易经 <问题>'. This creates ambiguity about when the skill should be invoked versus when ordinary discussion about business topics should not trigger it, and it provides no negative examples or tighter scope constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction '始终用商业语言输出' enforces a specific language/style mode for all responses, and the rest of the document provides no user opt-in or alternative locale/language choice. Under the policy, fixed language or locale constraints should be optional or clearly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to write an .html file to local storage without an explicit user-facing warning or confirmation step. Any capability that modifies the filesystem can surprise users, overwrite existing files, or create artifacts containing sensitive business content, especially in a broadly triggered business-assistant context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructional content in Chinese, including headings, definitions, and usage guidance, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire template is written as a mandatory Chinese-language analysis format, with no indication that users may choose another language or locale. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely written in Chinese and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule for natural-language violations, a fixed language without opt-in or justification is a reportable locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

All user-facing content in this file is Chinese, and there is no indication that the skill offers multilingual support, asks for user language preference, or is intentionally limited to a Chinese-language audience for a documented reason. That can violate language/locale policy when a skill implicitly forces a language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes a '快速匹配信号词' section mapping many common conversational phrases such as '再看看', '调研一下', '该不该投', and '可持续吗' to outcomes, but it does not define when these phrases should or should not activate the skill. Because these are common expressions in ordinary discussion and there are no exclusion conditions or negative examples, the trigger scope is overly broad and may cause unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance uses broad natural-language triggers such as '生成报告', '输出PDF', and '画个卦象图', which can overlap with ordinary user requests and cause the skill behavior to activate outside a clearly scoped command path. In a system with multiple tools or skills, this increases the risk of unintended file reads/writes and report generation actions being performed when the user did not explicitly invoke this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template hard-codes the document language as "zh-CN", which imposes a specific locale for generated output. Under the policy, locale restrictions should either be user-selectable or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file tells the reader to match based on prominent keywords, business stage, and core contradiction, but it does not define explicit trigger phrases, decision rules, or negative examples for when the skill should not be used. Because these dimensions are broad and common across many business conversations, the activation scope is underspecified and may lead to unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Phrases like "太卷了", "活不下去了", "该定什么价", and "要不要加码" are short, generic expressions that can arise in many contexts and are not uniquely tied to this skill. Without narrower constraints or surrounding context requirements, these examples risk causing the skill to match routine discussion too broadly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions and guidance exclusively in Chinese, and there is no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rule for natural-language violations, forcing a specific language without user choice is reportable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file presents all instructions and usage guidance exclusively in Chinese, which can amount to a language-policy violation when no user opt-in or alternative language support is offered. The file does not indicate that the skill is region-specific or intentionally restricted to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes a trigger-like usage description that effectively covers any scenario involving bringing different people together. That phrasing is broad enough to overlap with many ordinary workplace situations, and the file does not provide narrowing constraints or negative examples to clarify when the model should not be used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

该 markdown 文件适用 SQP-1。'什么时候你会用到这个模型' 下的多条情境描述较为开放,尤其是“任何‘有能力但选择不张扬’的策略时刻”范围非常宽,且没有明确触发短语、边界条件或排除示例,容易与大量日常管理/策略讨论重叠。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and guidance exclusively in Chinese, with no indication that the user can choose another language or that the locale is intentionally limited. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes a trigger-like usage condition: "任何'坐在办公室解决不了问题'的时刻". That condition is highly subjective and broad, with no constraints or negative examples, so it could cause the skill to be treated as applicable in many everyday situations rather than a clearly bounded context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file explicitly frames situations as requiring forceful action, punishment, and dealing with people or processes where 'must come down hard' is appropriate, but it does not add safeguards about lawful authority, due process, proportionality, HR/legal review, or risks of abuse. In a business decision skill, this can normalize punitive escalation and encourage users to apply coercive organizational actions against individuals without adequate governance, creating risk of harassment, retaliation, or improper disciplinary action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown skill presents all instructions and usage guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file presents all instructional content in a single language and does not indicate that the user can choose another language or that the skill is intentionally restricted to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The content explicitly prescribes gender-specific roles ('女正位乎内,男正位乎外') as a governance principle without contextualization, opt-in, or clear framing as a historical quotation rather than actionable modern guidance. In a business decision skill, this can normalize discriminatory role assignment, bias organizational decisions, and expose users to HR, legal, and ethical harm if applied in hiring, promotion, or leadership structuring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file's instructional content is fully presented in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill content is presented only in Chinese and does not offer any language or locale choice. Under the policy for natural-language violations, a skill that effectively forces a specific language without user opt-in should be flagged unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. The policy explicitly calls for flagging language or locale constraints when they are forced without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.