Back to skill

Security audit

my skill

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese industry-report generation skill that coherently uses web research and local report files without hidden persistence or destructive behavior.

Install this if you want Chinese-language industry analysis reports. Expect the agent to search the web, cite sources, read the bundled report template, and create an HTML or PDF report file in the working directory; for brief or casual questions, confirm whether you want the full report workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and all template instructions are written exclusively in Chinese, which effectively constrains generated output to Chinese. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific compliance reason, so this appears to be a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's natural-language guidance is exclusively in Chinese, including headings, rules, and examples, with no indication that users may choose another language or that the skill is limited to a Chinese-only workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to match many ordinary requests about whether an industry is 'good' or 'worth entering', which can cause the skill to activate in contexts the user did not explicitly intend. Because this skill performs web searches and generates local files, over-triggering increases the chance of surprising tool use, unnecessary data retrieval, and unintended file creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly instructs the agent to perform web searches, read a local reference file, and generate HTML/PDF output, but the skill description does not warn users that external retrieval and local file creation will occur. This weakens informed consent and can lead to unexpected network access or artifact creation in environments where users may assume a normal text-only response.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.