Back to skill

Security audit

jd-quicklearn

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused job-description learning-guide helper with disclosed research and optional Markdown output, and I found no evidence of hidden, destructive, or privilege-seeking behavior.

Installers should expect the skill to use the JD or role details they provide, perform public web research when needed, and possibly create a local Markdown guide when a file deliverable is requested. Non-Chinese users may want the publisher to clarify that responses should follow the user's preferred language.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language instructions and examples are entirely in Chinese, which can amount to forcing a specific language without user opt-in. The policy allows locale constraints when they are explicitly documented and justified or when users are given a language choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description defines broad trigger conditions such as analyzing a provided JD, researching a role, quickly understanding a position, learning department business, or filling knowledge gaps. These overlap with many normal career-help requests, increasing the chance the agent invokes this skill when a narrower or different skill would be more appropriate. In practice, this can cause incorrect routing, unnecessary external research, or policy-boundary drift into adjacent tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill metadata and body are written only in Chinese and do not state a language-selection rule based on user preference or conversation context. If the orchestrator treats the skill description literally, it may bias execution toward Chinese output or make behavior inconsistent for users interacting in other languages. This is primarily a usability and routing safety issue rather than a direct security exploit.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README states that the skill will '默认生成' a Markdown file deliverable, which implies a file-write side effect. In a markdown skill description, file creation affecting the user's workspace should be disclosed with a brief warning or expectation-setting note.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.