Back to skill

Security audit

AI Translator Pro by YQG

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only translation skill with disclosed optional file or Feishu document output, so it is generally safe but users should be careful before sending sensitive text to external documents.

Install this as a normal translator skill, but only ask it to write files or create Feishu documents when you intend that content to be saved there; avoid using external document output for confidential text unless that destination is approved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction defaults output to Chinese or English when the user does not specify a target language, which imposes a language choice automatically. This is a locale/language policy concern because the skill does not ask for user preference or offer an opt-in before selecting the output language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger "Any request involving converting text from one language to another" is extremely broad and lacks scope limits or exclusion conditions. This could cause the skill to activate on a wide range of ordinary conversation or adjacent editing tasks without clear boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a zero-dependency, pure prompt-driven translator, but its documented delivery options include writing files and creating/writing Feishu documents. This creates a capability mismatch that can mislead operators and users about side effects, increasing the risk of unintended external writes or data handling beyond expected translation-only behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Including Feishu document creation/writing introduces an external data exfiltration and persistence channel that is not central to a basic translator skill. If invoked on sensitive source text, the skill could send confidential content to a third-party document system, which materially expands risk compared with an in-chat translation-only workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.