Back to skill

Security audit

MEWP- aerial work machinery

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language MEWP engineering and bidding assistant with local calculations and clear safety caveats, not hidden or deceptive behavior.

Before installing, treat its calculations and equipment recommendations as preliminary engineering support only. Verify manufacturer data, current standards, site conditions, and safety-critical decisions with qualified professionals; confirm explicitly before enabling any recurring bid-monitoring automation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/bid_response_template.csv (reported line 1)May include surrounding context.

text
序号,招标要求(技术参数/条款),投标响应(型号/参数/方案),偏离说明(无偏离/正偏离/负偏离),备注
1,整机型式与平台高度,,,
2,额定载荷,,,
3,水平伸距/作业范围,,,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly tailors output to a specific user group and mandates Chinese-language output without offering user choice. This can exclude users, cause misunderstandings in safety-critical engineering and bidding contexts, and reduce the user's ability to verify technical details if they are more comfortable in another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill file is written as a prescriptive methodology in Chinese and includes output-format instructions such as line L55 requiring specific wording, but it does not state that language choice is optional or user-configurable. Under the policy rule for language/locale, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This guidance supports selection of mobile elevating work platforms, which is safety-critical because incorrect machine choice can lead to instability, overloading, inadequate ground bearing capacity, or unsafe wind/clearance assumptions. Although the file includes a note that values are only for preliminary screening and should be checked against manufacturer data, it does not clearly instruct the user to obtain qualified engineering and safety review before relying on the output for real-world deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language instructions and warnings that force a specific language/locale for all users. The policy allows locale constraints only when the skill offers opt-in or clearly documents a justified region-specific limitation, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This CSV template uses Chinese headers and field labels throughout, which imposes a specific language on users. Under the policy, a forced language or locale without user opt-in can be a natural-language policy violation when no alternative or choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.