Back to skill

Security audit

智能课堂

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed classroom lesson-design skill with a small local JSON validator and no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install this skill if you want Chinese-language classroom planning assistance and local lesson JSON validation. Avoid providing real student private data or credentials, and treat the bundled validator as a convenience check rather than a hardened service for untrusted bulk input.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/validate_lesson.py:17
Finding

Unhandled Null Array Fields Cause Validator Denial of Service

Content
View full analysis

Vulnerability Details

File Location: scripts/validate_lesson.py, lines 17–48
Vulnerability Type: Improper input type handling resulting in an uncaught exception
Risk Level: Low

python
for key in ("assumptions", "objectives", "agenda", "slides", "activities", "quiz", "homework"):
    if not isinstance(data.get(key), list):
        errors.append(f"{key}: must be an array")
for index, item in enumerate(data.get("agenda", [])):
    if not isinstance(item, dict):
        errors.append(f"agenda[{index}]: must be an object")
        continue
    for key in ("title", "teacher_action", "learner_action", "check"):
        if not isinstance(item.get(key), str) or not item[key].strip():
            errors.append(f"agenda[{index}].{key}: must be a non-empty string")
    minutes = item.get("minutes")
    if not isinstance(minutes, int) or isinstance(minutes, bool) or minutes <= 0:
        errors.append(f"agenda[{index}].minutes: must be a positive integer")
if isinstance(duration, int) and not isinstance(duration, bool) and all(
    isinstance(item, dict) and isinstance(item.get("minutes"), int) and not isinstance(item.get("minutes"), bool)
    for item in data.get("agenda", [])
):
    total = sum(item["minutes"] for item in data.get("agenda", []))
    if total != duration:
        errors.append(f"agenda minutes total {total}, expected duration_minutes {duration}")
for section, fields in {
    "slides": ("title", "key_point", "teacher_notes"),
    "activities": ("title", "mode", "instructions", "expected_observation", "fallback"),
    "quiz": ("question", "answer", "explanation", "next_step"),
}.items():
    for index, item in enumerate(data.get(section, [])):
        if not isinstance(item, dict):
            errors.append(f"{section}[{index}]: must be an object")
            continue
        for key in fields:
            if not isinstance(item.get(key), str) or not item[key].strip
...[truncated 2310 chars]
Remediation
View remediation

Remediation Suggestions

Normalize or guard every collection before iterating over it. After recording a type error, nested validation should be skipped for that field.

A suitable approach is:

python
agenda = data.get("agenda")
if not isinstance(agenda, list):
    errors.append("agenda: must be an array")
    agenda = []

for index, item in enumerate(agenda):
    # Validate agenda entries.

for section, fields in section_fields.items():
    items = data.get(section)
    if not isinstance(items, list):
        errors.append(f"{section}: must be an array")
        continue
    for index, item in enumerate(items):
        # Validate section entries.

Use the normalized agenda variable consistently for iteration, duration checks, and summation. Apply equivalent guards to all expected arrays, including assumptions, objectives, slides, activities, quiz, and homework.

Add regression tests covering explicit null, strings, objects, numbers, and booleans for every array field. Tests should verify that malformed input produces controlled validation messages and the intended nonzero exit code without a traceback.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个内容创作/教学设计技能,核心能力应是根据主题或材料生成完整互动课堂方案。实际代码并不进行任何课程生成、讲义生成、活动设计、测验生成或 AI 角色编排;它只对一个现成的课堂 JSON 包执行模式与字段级校验,并输出错误信息或 OK 结果。虽然被校验的数据结构与课堂方案相关,可能是更大系统中的辅助工具,但该代码块本身的主要目的与声明的主要用途明显不同,因此构成描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow specifies a default of '中文' when key details are missing. This imposes a language choice by default rather than offering the user or teacher an explicit language preference, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest states an assumption of '中文授课' (Chinese-language instruction), which imposes a specific language context. Under the policy, locale or language constraints should either be optional, user-selected, or clearly justified as region-specific; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown schema uses Chinese throughout field examples and instructional text, which effectively constrains the skill content to a specific language. Under the policy rule, a forced language without user opt-in or an explicit justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.