Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 10. **渲染 HTML**:使用 `assets/report_template.html` 和 `assets/vehicle_visuals/` 下的本地资产。图片生成或网页图片抓取只是可选增强,不是硬依赖。
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed automotive competitive-intelligence report generator that relies on PatSnap/Zhihuiya data and local report assets, with no evidence of hidden execution, persistence, or data exfiltration.
Install this only if you are comfortable connecting authorized PatSnap/Zhihuiya MCP services and using them for automotive market, patent, literature, and supply-chain research. Expect Chinese-oriented reports by default, verify source permissions for any licensed data or crawling fallback, and do not treat generated patent analysis as legal advice.
Referenced artifact was not completely inspected
10. **渲染 HTML**:使用 `assets/report_template.html` 和 `assets/vehicle_visuals/` 下的本地资产。图片生成或网页图片抓取只是可选增强,不是硬依赖。
Referenced artifact was not completely inspected
10. **渲染 HTML**:使用 `assets/report_template.html` 和 `assets/vehicle_visuals/` 下的本地资产。图片生成或网页图片抓取只是可选增强,不是硬依赖。
Referenced artifact was not completely inspected
10. **渲染 HTML**:使用 `assets/report_template.html` 和 `assets/vehicle_visuals/` 下的本地资产。图片生成或网页图片抓取只是可选增强,不是硬依赖。
The skill instructions and examples are entirely written in Chinese, and there is no statement that users may interact in other languages or choose their preferred locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly justified as region-specific.
The HTML declares lang="zh-CN" and the report title/content are presented in Chinese as the default, which imposes a specific language/locale. Under the policy, locale constraints should either be optional for the user or clearly documented as region-specific and justified; this file does not provide such opt-in or justification.
The prescribed output format includes fixed Chinese labels (产品域 → 一级技术 → 二级配置/零部件 → 供应商类型 → 竞品/专利/供应链分析对象) as a required first display, which imposes a specific language/locale in the skill's natural-language behavior. The file does not provide an opt-in, fallback, or user language choice, so this is a language policy concern.
Lines L07-L10 set requirements in Chinese and name Chinese-specific reporting fields and source expectations, which effectively constrain the skill's operation to a specific language/locale. The file does not provide an opt-in, alternative locale handling, or a documented justification that this skill is intentionally region-specific.
Multiple demo prompts are written as direct Chinese-language output requests, and the file provides no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only regional context. This creates a natural-language locale policy concern because the examples consistently impose a specific language without user opt-in.
This markdown file includes mandatory methodology content in Chinese, and later sections continue to require Chinese labels for lifecycle stages. Because the file does not offer an English/Chinese option or explain that the skill is intentionally region-specific, it creates a language/locale policy concern under the natural-language policy rule.
The lifecycle taxonomy is defined using Chinese-only stage names such as 引领技术 and 退出技术. Requiring these labels without offering alternatives or stating a justified locale limitation can force a specific language on users and violates the stated policy criteria.
This markdown template includes mandatory field values in Chinese, such as lifecycle stages, which can force a specific language/locale in downstream outputs. The file also requires Chinese-only output text elsewhere, but does not provide user opt-in or explain that the skill is intentionally China/Chinese-specific.
The template instructs outputs to show the Chinese phrase "论文信号暂无,以专利为主" when no literature is available. Because this is prescribed output language rather than an example, it creates a language-policy issue unless the skill is explicitly documented as Chinese-only or offers localization.
This row defines relationship status values entirely in Chinese, which effectively constrains report language. The file does not indicate that this locale restriction is intentional or allow a configurable language option.
The final HTML is required to include the Chinese phrase "数据聚焦与服务对象," making the output language prescriptive. Without a documented regional scope or user opt-in, this is a natural-language locale policy violation.
The HTML rendering rules require the exact Chinese string "论文信号暂无,以专利为主" in final output. This forces a specific language in all generated reports unless the skill is explicitly scoped to that locale.
This markdown file contains prescribed Chinese-language output text such as the core chain states, which effectively imposes a locale on part of the report format. The policy allows locale constraints only when the skill offers user choice or clearly documents and justifies the region/language limitation, which is not present here.
The required '1-2 year technology state' values are specified only in Chinese, which creates a language policy issue when no opt-in or rationale is provided. This can force a specific locale in generated outputs regardless of user preference.
The skill mandates Chinese status labels for relationship reporting, but does not indicate that the skill is region-specific or that the user can select a language. That constitutes a natural-language locale policy violation under the provided rules.
These table entries define output states exclusively in Chinese, which constrains the generated report language. Because the file does not explain a region-specific requirement or offer opt-in language selection, this violates the language/locale policy.
The lifecycle taxonomy and guidance are expressed as required Chinese-language labels, but the skill does not tell users that it is limited to Chinese reporting or provide alternatives. This is a policy issue because it forces a specific language without opt-in.
The skill instructions begin in Chinese and state the service scope in Chinese, with much of the operational taxonomy and required output labels also fixed in Chinese. There is no indication that users may choose another language or locale, which can violate language-choice policy when not explicitly justified as a region-specific tool.
The file’s user-facing instructions and warnings are presented only in Chinese, which can force a specific language on users without opt-in. The policy for natural-language issues applies to all file types, and there is no indication that this skill is intentionally limited to Chinese-speaking users or a specific region.
The usage_note at L011 is written only in Chinese, which can impose a language-specific constraint on downstream users or tools consuming this metadata. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy concern.
No suspicious patterns detected.