Back to skill

Security audit

batch-lesson-plan

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Chinese lesson-plan document generator with disclosed file processing and no evidence of hidden credential access, persistence, or remote code execution.

Install only if you want a Chinese-language, local DOCX lesson-plan workflow. Provide your own trusted templates and PDFs, review generated content for accuracy, and avoid pointing the output argument at an existing important file because the helper script overwrites that path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 22)May include surrounding context.

text
!examples/**/*.docx

# 用户/凭据
.env
*.token
*.pem

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码块的核心功能是:1)分析传入 docx 模板中的首个表格结构;2)从 JSON 读取字段和单元格内容;3)直接修改 document.xml 将内容填入模板;4)对生成结果做结构校验。这只覆盖了声明流程中的后半段一小部分(内容 JSON -> 生成单个 docx -> 结构校验),而声明中的关键前置能力——解析《授课计划》、提取课次、读取扫描教材 PDF 原文、依据这些信息生成整套教案内容——均未出现。代码也没有批量处理多份教案的循环或任务编排逻辑。因此,声明描述的是一个端到端、批量化的教案生成技能,而实际代码只是其中的底层文档填充组件,存在明显能力范围不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill is written entirely in Chinese and describes its purpose specifically around generating Chinese vocational-school lesson plans, but it does not explicitly state that it is a Chinese-only or China-specific skill. Under the policy, forcing a specific language/locale without user opt-in or a clearly documented justified constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The sample values and templates throughout the file are entirely in Chinese, indicating the skill or template is intended to produce Chinese-language content by default. Because there is no accompanying opt-in, alternative locale option, or documented region-specific justification in this file, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool unconditionally deletes an existing output path before rewriting it, with no confirmation, backup, atomic temp-file strategy, or path safety checks. In a batch document-generation workflow, a mistaken or attacker-influenced output path can overwrite or destroy arbitrary user files the process has permission to modify, causing data loss and potentially clobbering important documents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill's stated purpose is converting lesson plans and scanned textbook content into lesson-plan .docx files, which is a local document-processing workflow. The README additionally points users to an external WorkBuddy website for conversation archives, introducing a network-facing capability/reference that is not justified by the core document-conversion purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest frames this skill as a local workflow for parsing teaching plans, reading textbook PDFs, generating JSON, and producing DOCX files. Linking users to a remote WorkBuddy conversation archive introduces an external network capability that is not justified as part of the stated document-generation purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This JSON file is entirely written in Chinese and presents fixed instructional content with no indication that users can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language documentation and interface strings are entirely Chinese, with no indication that the user can choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.