Ae4
- Category
- analysis-evasion
- Confidence
- 80% confidence
- Finding
Suspicious Unicode normalization or mixed-script content
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a straightforward Chinese-language motor quality inspection/report generator with only user-directed local report output.
Install only if a Chinese-language GJB-style motor inspection assistant fits your workflow. When using the report script, choose the --output path deliberately because the script writes directly to that file if requested.
Suspicious Unicode normalization or mixed-script content
The skill includes commands that generate output files (for example, using '--output oqc_report_20240020.txt') but does not declare any tool scope such as allowed-tools or permissions. This creates an authorization ambiguity where an agent may infer file-write behavior from the markdown and write files without an explicit least-privilege declaration, increasing the risk of unintended filesystem modification.
The skill metadata and all user-facing instructions are written exclusively in Chinese, which effectively imposes a language choice on users. Under the policy, locale or language constraints should be optional or explicitly justified; this file does not indicate opt-in language selection or explain why Chinese is required.
Suspicious Unicode normalization or mixed-script content
This Python file contains natural-language documentation and command help text that assumes Chinese as the only language for users. The policy specifically calls for flagging language or locale constraints when the skill forces a specific language without user opt-in.
No suspicious patterns detected.