Back to skill

Security audit

Fuxi Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it should be reviewed because it profiles real people, stores generated research, and gives mixed messages about whether private user-provided materials may be used.

Review before installing if you may use it on private individuals or with confidential material. Treat generated research folders and persona skills as persistent records about real people, avoid providing internal documents unless you have rights to use them, and verify generated claims before sharing or relying on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
基于提炼出的核心要素,生成目标人物的 `SKILL.md` 文件。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
基于提炼出的核心要素,生成目标人物的 `SKILL.md` 文件。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly encourages users to enter any person's name and have the skill automatically research "across the web" to distill that person's thinking, but it does not clearly disclose that this may collect, process, and synthesize personal data about identifiable individuals. In a skill centered on profiling named people, that omission is significant because users may unknowingly generate personality summaries or dossiers from public data without understanding privacy, consent, or reputational risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description is written as an instruction set entirely in Chinese and specifies fixed response behavior for generated skills, without indicating that users may choose another language or locale. This can constitute a language/locale policy issue when a skill implicitly forces one language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description uses broad natural-language examples such as “提炼一个XXX的精华” and “帮我创建一个XXX的商业版Skill”, which could match many general brainstorming or writing requests. The file does not provide clear trigger boundaries, exclusions, or negative examples to distinguish when this skill should activate versus when a normal assistant response is intended.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims it uses only publicly available internet sources, but its workflow explicitly asks for and prioritizes user-provided first-hand materials such as internal speeches and documents. This creates a transparency and consent problem: users may disclose confidential or proprietary information under a misleading expectation about what data sources are being used.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The inline documentation repeats a 'public-source-only' assurance while the operational steps instruct the agent to solicit and use first-hand user materials. This contradiction can materially mislead users about privacy boundaries and provenance, increasing the risk of confidential data exposure or unauthorized reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to create directories/files and perform network-based research, but the user-facing description does not clearly warn about these side effects up front. Hidden side effects undermine informed consent and can lead to unwanted workspace modification, unnecessary external requests, or accidental handling of sensitive project context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire guide and all embedded prompts are written as fixed Chinese instructions, with no indication that another language may be used if the user prefers. This creates a language/locale constraint in the skill content without explicit user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire template mandates Chinese-language headings, instructions, disclosures, and response framing, with no indication that the user can choose another language. This can violate language/locale policy where skills should not force a specific language unless the constraint is explicit and justified or user-selected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition is broad enough that many ordinary prompts about a person’s perspective could activate the skill without clear domain or safety boundaries. Overbroad activation increases the risk of unintended persona use in sensitive contexts, including advice or judgments outside the intended commercial-consulting scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template expands the generated skill’s behavior from static persona synthesis into mandatory live research before answering factual or mixed questions. That increases the attack surface by enabling unbounded retrieval of external content at runtime, which can introduce prompt injection, unreliable sources, and behavior that no longer matches the declared distilled-framework purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template explicitly mandates tool use such as WebSearch for generated skills, even though the skill is presented as a persona distilled from public materials. Mandatory external tool use creates a direct channel for retrieval-based prompt injection and data-quality issues, and it can cause the generated persona to act on adversarial web content during normal interactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README states that each run outputs a full skill package, including research documents and generated artifacts, but it does not warn that these files may persist synthesized information about the target person. This creates a quieter privacy and governance risk: users may store, share, or reuse generated profiles without realizing they are creating durable records about real people.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.