Back to skill

Security audit

自然语言转JOSN参数

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese natural-language-to-JSON formatter with some broad activation and conversation-context reuse behavior, but no hidden execution, network use, persistence, or destructive capability.

Install this if you want Chinese natural-language prompts converted into a fixed JSON template. Be aware that broad JSON requests may route through this skill, and short follow-up requests may inherit fields from the previous conversion unless you make a fresh request explicit.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are extremely broad, matching generic requests like '转成JSON' or '用JSON格式输出' without limiting the skill to a narrow domain. This can cause the skill to activate on unrelated user tasks and silently reshape outputs according to its template, leading to incorrect behavior, misrouting, and unintended processing of user content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to inherit parameters from prior conversation turns without requiring explicit user confirmation or notifying the user that earlier data will be reused. This creates a risk that stale, sensitive, or contextually inappropriate parameters will be carried forward into new outputs, potentially disclosing prior user intent or data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the model to remember and reuse prior user-provided parameters across turns, which can retain and reintroduce previously supplied data even when the user did not intend that linkage. In a transformation skill that may process queries about entities, sources, and time ranges, this can result in unintended disclosure, cross-request contamination, and privacy issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example trigger phrases include many ambiguous everyday requests, such as asking for JSON formatting or organizing output as JSON, with no scope constraints. In an agent environment, this increases the chance of unintended invocation, causing the skill to intercept benign requests and transform user data into a fixed schema unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON eval file contains a trigger-style prompt, "帮我转换JSON,获取舆情数据", that is broad and could overlap with many ordinary requests for JSON conversion or public-opinion data retrieval. The file does not provide any narrowing conditions, explicit trigger list, or negative examples to clarify when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All natural-language examples and output instructions in this file are written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only context. This can violate a language/locale policy if the organization requires user choice or explicit documentation for locale restrictions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.