Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 基于提炼出的核心要素,生成目标人物的 `SKILL.md` 文件。
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not malicious, but it should be reviewed because it profiles real people, stores generated research, and gives mixed messages about whether private user-provided materials may be used.
Review before installing if you may use it on private individuals or with confidential material. Treat generated research folders and persona skills as persistent records about real people, avoid providing internal documents unless you have rights to use them, and verify generated claims before sharing or relying on them.
Referenced artifact was not completely inspected
基于提炼出的核心要素,生成目标人物的 `SKILL.md` 文件。
Referenced artifact was not completely inspected
基于提炼出的核心要素,生成目标人物的 `SKILL.md` 文件。
The README explicitly encourages users to enter any person's name and have the skill automatically research "across the web" to distill that person's thinking, but it does not clearly disclose that this may collect, process, and synthesize personal data about identifiable individuals. In a skill centered on profiling named people, that omission is significant because users may unknowingly generate personality summaries or dossiers from public data without understanding privacy, consent, or reputational risks.
The description is written as an instruction set entirely in Chinese and specifies fixed response behavior for generated skills, without indicating that users may choose another language or locale. This can constitute a language/locale policy issue when a skill implicitly forces one language without opt-in.
The activation description uses broad natural-language examples such as “提炼一个XXX的精华” and “帮我创建一个XXX的商业版Skill”, which could match many general brainstorming or writing requests. The file does not provide clear trigger boundaries, exclusions, or negative examples to distinguish when this skill should activate versus when a normal assistant response is intended.
The skill claims it uses only publicly available internet sources, but its workflow explicitly asks for and prioritizes user-provided first-hand materials such as internal speeches and documents. This creates a transparency and consent problem: users may disclose confidential or proprietary information under a misleading expectation about what data sources are being used.
The inline documentation repeats a 'public-source-only' assurance while the operational steps instruct the agent to solicit and use first-hand user materials. This contradiction can materially mislead users about privacy boundaries and provenance, increasing the risk of confidential data exposure or unauthorized reuse.
The skill instructs the agent to create directories/files and perform network-based research, but the user-facing description does not clearly warn about these side effects up front. Hidden side effects undermine informed consent and can lead to unwanted workspace modification, unnecessary external requests, or accidental handling of sensitive project context.
The entire guide and all embedded prompts are written as fixed Chinese instructions, with no indication that another language may be used if the user prefers. This creates a language/locale constraint in the skill content without explicit user opt-in or documented regional justification.
The entire template mandates Chinese-language headings, instructions, disclosures, and response framing, with no indication that the user can choose another language. This can violate language/locale policy where skills should not force a specific language unless the constraint is explicit and justified or user-selected.
The trigger condition is broad enough that many ordinary prompts about a person’s perspective could activate the skill without clear domain or safety boundaries. Overbroad activation increases the risk of unintended persona use in sensitive contexts, including advice or judgments outside the intended commercial-consulting scope.
The template expands the generated skill’s behavior from static persona synthesis into mandatory live research before answering factual or mixed questions. That increases the attack surface by enabling unbounded retrieval of external content at runtime, which can introduce prompt injection, unreliable sources, and behavior that no longer matches the declared distilled-framework purpose.
The template explicitly mandates tool use such as WebSearch for generated skills, even though the skill is presented as a persona distilled from public materials. Mandatory external tool use creates a direct channel for retrieval-based prompt injection and data-quality issues, and it can cause the generated persona to act on adversarial web content during normal interactions.
The README states that each run outputs a full skill package, including research documents and generated artifacts, but it does not warn that these files may persist synthesized information about the target person. This creates a quieter privacy and governance risk: users may store, share, or reuse generated profiles without realizing they are creating durable records about real people.
No suspicious patterns detected.