Back to skill

Security audit

confucius-ai-conversation

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only Confucius conversation skill with broad persona triggers but no hidden code, persistence, credential access, or data-moving behavior.

Install this if you want a Confucius/Analects-style conversational helper. Be aware it may activate for broad life-advice questions and answer in a strong persona style, so use a neutral assistant or specialist support for medical, legal, mental-health, or other high-stakes topics.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is extremely broad, covering generic life problems, classical wisdom requests, and many common terms such as 'life', 'learning', and 'interpersonal' themes. This can cause the skill to activate outside its intended niche, leading to misrouting, persona hijacking of unrelated conversations, and increased chance that users receive stylized guidance where a more appropriate domain-specific skill or safer baseline response should apply.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation conditions include broad categories like life guidance, conduct, learning methods, and wisdom-seeking, which are common across many ordinary user conversations. In context, this makes the skill more dangerous because it is a high-persona, style-constraining skill that could inappropriately capture sensitive or ambiguous requests, including situations better handled by neutral assistance or specialized safety-aware flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Line L115 directs the skill to '以孔子口吻白話轉述', which imposes a specific speaking style on outputs. Under the policy rule for natural-language constraints, forcing a particular language/locale or comparable presentation mode without user choice can be a policy concern when no opt-in or alternative is offered in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The filename and metadata present this as a Traditional Chinese-focused resource, with the primary title at L003 in Traditional Chinese and language variants listed afterward. While the file also includes zh_cn and en content, the natural-language presentation appears to privilege a specific locale/script without any stated user choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The metadata restricts the dataset to three specific language/locale variants: zh_tw, zh_cn, and en. Under the policy, locale constraints should either offer user choice or be clearly documented as a justified region-specific limitation; this file lists fixed locales but does not state any opt-in or selection behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest-like JSON explicitly restricts content to zh_tw, zh_cn, and en. Under the policy rule for language/locale, a fixed language set can be a violation when the file imposes locale behavior without offering user choice or documenting an opt-in mechanism.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a JSON manifest file, so vague-trigger review applies. The file provides descriptive metadata such as languages but contains no explicit invocation phrases, scope limits, or exclusion conditions, leaving activation boundaries underspecified if this manifest is used for routing or matching.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.