Back to skill

Security audit

rd-direction-finder

Security checks for vulnerabilities and agentic risk

Overview

The skill’s research-report workflow is mostly coherent, but its generated HTML reports can preserve active user or search-result markup, creating a real browser-side injection risk.

Review before installing if you will handle confidential R&D text. The skill may send the problem description to external search/MCP services and writes reports to disk. Do not open generated HTML from untrusted payloads or untrusted search content unless the renderer is fixed to escape or sanitize HTML and add a restrictive content security policy.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_report.py:1571
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
str: if s is None: return "" return str(s).replace("\r\n", "\n").replace("\r", "\n").strip() ``` The user-controlled requirement is incorporated directly into the generated Markdown: ```python def build_markdown_report(payload: Dict[str, Any]) -> str: """Build the exact Step 4 report body defined by SKILL.md/report-template.md.""" meta = _get(payload, "meta") or {} project_name = md_text(_get(meta, "project_name")) applicant = md_text(_get(meta, "applicant")) today_iso = md_text(_get(meta, "today_iso")) scope = md_text(_get(meta, "scope")) or "专利+论文+网络学术文献补充" requirement = md_text(_get(payload, "requirement_text")) or "未提及" analysis = _get(payload, "analysis") or {} summary = _get(payload, "summary") or {} issues = _list(payload, "issues") directions = _list(payload, "directions") units = _list(payload, "units") app = _get(payload, "appendix") or {} parts: List[str] = ["## 科研需求检索报告", ""] # ... parts.extend(["> **需求输入原文:**", ">", *["> " + line for line in requirement.split("\n")], ""]) ``` Raw HTML is then explicitly enabled during Markdown rendering: ```python def render_markdown_report(markdown_text: str) -> str: markdown_text = group_appendices_by_route(markdown_text) renderer = mistune.create_markdown(escape=False, plugins=["table"]) html_text = renderer(markdown_text) ``` A complete payload-provided Markdown document is also accepted as the preferred rendering source without sanitization: ```python def build_report_markdown(payload: Dict[str, Any]) -> str: payload = normalize_payload(payload) return md_text ...[truncated 3208 chars]
Remediation
View remediation
str: url = str(value or "").strip() parsed = urlparse(url) if parsed.scheme.lower() not in {"https", "http"}: return "" return url ``` 5. Add a restrictive Content Security Policy to the generated document as defense in depth. For a self-contained report with no scripts, an appropriate starting point is: ```html ``` Avoid allowing scripts unless they are essential. 6. Add regression tests that render malicious values through both `requirement_text` and `markdown_report`. Tests should verify that the generated HTML does not contain executable forms of: - `` - `` - `` - `[link](javascript:alert(1))` - Raw forms ...[truncated 258 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises multi-source retrieval and analytical generation, but the embedded workflow mainly renders and serializes pre-supplied structured data. This mismatch is dangerous because users may trust the output as evidence-backed research when the skill may simply transform unverified inputs into authoritative-looking Markdown/HTML reports.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
4. `HTML 报告`:由 `scripts/render_report.py` 读取 payload 生成,写入 `<HTML_PATH>`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
4. `HTML 报告`:由 `scripts/render_report.py` 读取 payload 生成,写入 `<HTML_PATH>`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 539)May include surrounding context.

md
4. `HTML 报告`:由 `scripts/render_report.py` 读取 payload 生成,写入 `<HTML_PATH>`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 593)May include surrounding context.

md
4. `HTML 报告`:由 `scripts/render_report.py` 读取 payload 生成,写入 `<HTML_PATH>`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
路径定义见 [assets/paths.md](assets/paths.md),payload schema 见 [assets/payload-schema.md](assets/payload-schema.md),报告结构见 [assets/report-template.md](assets/report-t

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs reading and writing local artifacts (MD_PATH, PAYLOAD_PATH, HTML_PATH) yet declares no tool scope or permission boundary. In an agent setting, missing scope declarations can let the skill access broader file capabilities than users expect, increasing the risk of unauthorized local file modification or data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs patent, paper, and Web searches using user-provided problem_text but provides no privacy warning that this content may be sent to external services. If users submit confidential R&D plans, trade secrets, or unpublished technical details, the skill could exfiltrate sensitive data to third-party platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description and required report structure are entirely specified in Chinese, including fixed Chinese section titles and trigger phrases, with no indication that users may choose another language. This constitutes a language/locale policy concern because the skill appears to require a specific language without explicit opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill mandates automatic creation of Markdown, JSON payload, and HTML artifacts as part of normal execution without an explicit user-facing consent step. Automatic local writes can overwrite files, leave sensitive research data on disk, and create persistence side effects users did not knowingly authorize.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

md
**数据准备**:Step 0–4 生成的全部结构化数据,通过 shell 环境变量传入 Python。以下变量名与 payload schema 字段一一对应:

| 环境变量           | 对应 payload 字段  | 内容说明                                                                                                                                                                                                                        | 必填 |
| :----------------- | :----------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--: |
| `META_JSON`        | `meta`             | JSON 字符串:`{"today_iso": "YYYY-MM-DD", "project_name": "...", "applicant": "..."}`                                                                                                                                           |  是  |
| `REQUIREMENT_TEXT` | `requirement_text` | 原始需求文本(纯文本)                                                                                                                                                                                                          |  是  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
| 环境变量           | 对应 payload 字段  | 内容说明                                                                                                                                                                                                                        | 必填 |
| :----------------- | :----------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--: |
| `META_JSON`        | `meta`             | JSON 字符串:`{"today_iso": "YYYY-MM-DD", "project_name": "...", "applicant": "..."}`                                                                                                                                           |  是  |
| `REQUIREMENT_TEXT` | `requirement_text` | 原始需求文本(纯文本)                                                                                                                                                                                                          |  是  |
| `ANALYSIS_JSON`    | `analysis`         | JSON 字符串:`{"demand": {"scene": "...", "pain": "...", "current": "..."}, "bottleneck": {"limit": "...", "cost": "...", "principle": "..."}, "solution": {"path": "...", "system": "...", "compat": "...", "target": "..."}}` |  是  |
| `ISSUES_JSON`      | `issues`           | JSON 字符串:`[{"no": "T1", "name": "...", "desc": "..."}]`                                                                                                                                                                     |  是  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
| 环境变量           | 对应 payload 字段  | 内容说明                                                                                                                                                                                                                        | 必填 |
| :----------------- | :----------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--: |
| `META_JSON`        | `meta`             | JSON 字符串:`{"today_iso": "YYYY-MM-DD", "project_name": "...", "applicant": "..."}`                                                                                                                                           |  是  |
| `REQUIREMENT_TEXT` | `requirement_text` | 原始需求文本(纯文本)                                                                                                                                                                                                          |  是  |
| `ANALYSIS_JSON`    | `analysis`         | JSON 字符串:`{"demand": {"scene": "...", "pain": "...", "current": "..."}, "bottleneck": {"limit": "...", "cost": "...", "principle": "..."}, "solution": {"path": "...", "system": "...", "compat": "...", "target": "..."}}` |  是  |
| `ISSUES_JSON`      | `issues`           | JSON 字符串:`[{"no": "T1", "name": "...", "desc": "..."}]`                                                                                                                                                                     |  是  |
| `DIRECTIONS_JSON`  | `directions`       | JSON 字符串(含 evidence),见下表                                                                                                                                                                                              |  是  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

md
| `META_JSON`        | `meta`             | JSON 字符串:`{"today_iso": "YYYY-MM-DD", "project_name": "...", "applicant": "..."}`                                                                                                                                           |  是  |
| `REQUIREMENT_TEXT` | `requirement_text` | 原始需求文本(纯文本)                                                                                                                                                                                                          |  是  |
| `ANALYSIS_JSON`    | `analysis`         | JSON 字符串:`{"demand": {"scene": "...", "pain": "...", "current": "..."}, "bottleneck": {"limit": "...", "cost": "...", "principle": "..."}, "solution": {"path": "...", "system": "...", "compat": "...", "target": "..."}}` |  是  |
| `ISSUES_JSON`      | `issues`           | JSON 字符串:`[{"no": "T1", "name": "...", "desc": "..."}]`                                                                                                                                                                     |  是  |
| `DIRECTIONS_JSON`  | `directions`       | JSON 字符串(含 evidence),见下表                                                                                                                                                                                              |  是  |
| `SUMMARY_JSON`     | `summary`          | JSON 字符串:`{"cnt_case": N, "cnt_paper": N, "cnt_patent": N, "cnt_web": N, "cnt_org_total": N, "cnt_org_top5": N, "top_orgs": "..."}`                                                                                         |  是  |
| `UNITS_JSON`       | `units`            | JSON 字符串:`[{"name": "...", "covers": ["..."], "focus": "...", "achievements": "...", "cites": ["S#"]}]`                                                                                                                     |  是  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

md
| `REQUIREMENT_TEXT` | `requirement_text` | 原始需求文本(纯文本)                                                                                                                                                                                                          |  是  |
| `ANALYSIS_JSON`    | `analysis`         | JSON 字符串:`{"demand": {"scene": "...", "pain": "...", "current": "..."}, "bottleneck": {"limit": "...", "cost": "...", "principle": "..."}, "solution": {"path": "...", "system": "...", "compat": "...", "target": "..."}}` |  是  |
| `ISSUES_JSON`      | `issues`           | JSON 字符串:`[{"no": "T1", "name": "...", "desc": "..."}]`                                                                                                                                                                     |  是  |
| `DIRECTIONS_JSON`  | `directions`       | JSON 字符串(含 evidence),见下表                                                                                                                                                                                              |  是  |
| `SUMMARY_JSON`     | `summary`          | JSON 字符串:`{"cnt_case": N, "cnt_paper": N, "cnt_patent": N, "cnt_web": N, "cnt_org_total": N, "cnt_org_top5": N, "top_orgs": "..."}`                                                                                         |  是  |
| `UNITS_JSON`       | `units`            | JSON 字符串:`[{"name": "...", "covers": ["..."], "focus": "...", "achievements": "...", "cites": ["S#"]}]`                                                                                                                     |  是  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 327)May include surrounding context.

md
| `ANALYSIS_JSON`    | `analysis`         | JSON 字符串:`{"demand": {"scene": "...", "pain": "...", "current": "..."}, "bottleneck": {"limit": "...", "cost": "...", "principle": "..."}, "solution": {"path": "...", "system": "...", "compat": "...", "target": "..."}}` |  是  |
| `ISSUES_JSON`      | `issues`           | JSON 字符串:`[{"no": "T1", "name": "...", "desc": "..."}]`                                                                                                                                                                     |  是  |
| `DIRECTIONS_JSON`  | `directions`       | JSON 字符串(含 evidence),见下表                                                                                                                                                                                              |  是  |
| `SUMMARY_JSON`     | `summary`          | JSON 字符串:`{"cnt_case": N, "cnt_paper": N, "cnt_patent": N, "cnt_web": N, "cnt_org_total": N, "cnt_org_top5": N, "top_orgs": "..."}`                                                                                         |  是  |
| `UNITS_JSON`       | `units`            | JSON 字符串:`[{"name": "...", "covers": ["..."], "focus": "...", "achievements": "...", "cites": ["S#"]}]`                                                                                                                     |  是  |

`DIRECTIONS_JSON` 中每个方向对象的必填结构:

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
| `ISSUES_JSON`      | `issues`           | JSON 字符串:`[{"no": "T1", "name": "...", "desc": "..."}]`                                                                                                                                                                     |  是  |
| `DIRECTIONS_JSON`  | `directions`       | JSON 字符串(含 evidence),见下表                                                                                                                                                                                              |  是  |
| `SUMMARY_JSON`     | `summary`          | JSON 字符串:`{"cnt_case": N, "cnt_paper": N, "cnt_patent": N, "cnt_web": N, "cnt_org_total": N, "cnt_org_top5": N, "top_orgs": "..."}`                                                                                         |  是  |
| `UNITS_JSON`       | `units`            | JSON 字符串:`[{"name": "...", "covers": ["..."], "focus": "...", "achievements": "...", "cites": ["S#"]}]`                                                                                                                     |  是  |

`DIRECTIONS_JSON` 中每个方向对象的必填结构:

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
81% confidence
Finding

The skill contains extremely verbose, rigid formatting and compliance instructions that consume context budget and can crowd out higher-priority safety signals or user intent. In agent systems, this can degrade reliable decision-making and increase the chance the model follows template-completion behavior over security-aware behavior, especially when also handling file writes and external searches.

Content

Scanner excerpt · SKILL.md (reported line 557)May include surrounding context.

md
## 质量规则

| 规则编号 | 约束内容                                                                                                                                                                                                                                                                                                 |
| :------: | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|    Q1    | 报告头部必须包含两个前置模块(缺一视为交付不合格):①元信息 blockquote 块、②需求原文 blockquote 块;两者均置于 Step 0 三维表和所有正文章节之前。具体字段、渲染规则与"未识别整行删除"逻辑以 [assets/report-template.md](assets/report-template.md) 「顶部元信息块」「需求输入原文」两节为准,本表不重复。 |
|    Q2    | Step 1 表格必须紧接 Step 0,先于研发路线输出                                                                                                                                                                                                                                                             |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 557)May include surrounding context.

md
## 质量规则

| 规则编号 | 约束内容                                                                                                                                                                                                                                                                                                 |
| :------: | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|    Q1    | 报告头部必须包含两个前置模块(缺一视为交付不合格):①元信息 blockquote 块、②需求原文 blockquote 块;两者均置于 Step 0 三维表和所有正文章节之前。具体字段、渲染规则与"未识别整行删除"逻辑以 [assets/report-template.md](assets/report-template.md) 「顶部元信息块」「需求输入原文」两节为准,本表不重复。 |
|    Q2    | Step 1 表格必须紧接 Step 0,先于研发路线输出                                                                                                                                                                                                                                                             |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 560)May include surrounding context.

md
| 规则编号 | 约束内容                                                                                                                                                                                                                                                                                                 |
| :------: | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|    Q1    | 报告头部必须包含两个前置模块(缺一视为交付不合格):①元信息 blockquote 块、②需求原文 blockquote 块;两者均置于 Step 0 三维表和所有正文章节之前。具体字段、渲染规则与"未识别整行删除"逻辑以 [assets/report-template.md](assets/report-template.md) 「顶部元信息块」「需求输入原文」两节为准,本表不重复。 |
|    Q2    | Step 1 表格必须紧接 Step 0,先于研发路线输出                                                                                                                                                                                                                                                             |
|    Q3    | 技术难题编号统一使用 T1、T2…TN;攻关方向统一使用方向①②③…;[S#] 全局唯一                                                                                                                                                                                                                                  |
|    Q4    | 攻关方向数量 k = min(N, max_directions),可合并同类项但不得遗漏任何难题                                                                                                                                                                                                                                  |
|    Q5    | 每路研发内容不少于 3 条,且每条至少关联 1 个 [S#] 证据                                                                                                                                                                                                                                                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 561)May include surrounding context.

md
| :------: | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|    Q1    | 报告头部必须包含两个前置模块(缺一视为交付不合格):①元信息 blockquote 块、②需求原文 blockquote 块;两者均置于 Step 0 三维表和所有正文章节之前。具体字段、渲染规则与"未识别整行删除"逻辑以 [assets/report-template.md](assets/report-template.md) 「顶部元信息块」「需求输入原文」两节为准,本表不重复。 |
|    Q2    | Step 1 表格必须紧接 Step 0,先于研发路线输出                                                                                                                                                                                                                                                             |
|    Q3    | 技术难题编号统一使用 T1、T2…TN;攻关方向统一使用方向①②③…;[S#] 全局唯一                                                                                                                                                                                                                                  |
|    Q4    | 攻关方向数量 k = min(N, max_directions),可合并同类项但不得遗漏任何难题                                                                                                                                                                                                                                  |
|    Q5    | 每路研发内容不少于 3 条,且每条至少关联 1 个 [S#] 证据                                                                                                                                                                                                                                                   |
|    Q6    | 总结表必须包含"对应难题"列,明确标注每路方向覆盖的 T# 编号                                                                                                                                                                                                                                               |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 562)May include surrounding context.

md
| :------: | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|    Q1    | 报告头部必须包含两个前置模块(缺一视为交付不合格):①元信息 blockquote 块、②需求原文 blockquote 块;两者均置于 Step 0 三维表和所有正文章节之前。具体字段、渲染规则与"未识别整行删除"逻辑以 [assets/report-template.md](assets/report-template.md) 「顶部元信息块」「需求输入原文」两节为准,本表不重复。 |
|    Q2    | Step 1 表格必须紧接 Step 0,先于研发路线输出                                                                                                                                                                                                                                                             |
|    Q3    | 技术难题编号统一使用 T1、T2…TN;攻关方向统一使用方向①②③…;[S#] 全局唯一                                                                                                                                                                                                                                  |
|    Q4    | 攻关方向数量 k = min(N, max_directions),可合并同类项但不得遗漏任何难题                                                                                                                                                                                                                                  |
|    Q5    | 每路研发内容不少于 3 条,且每条至少关联 1 个 [S#] 证据                                                                                                                                                                                                                                                   |
|    Q6    | 总结表必须包含"对应难题"列,明确标注每路方向覆盖的 T# 编号                                                                                                                                                                                                                                               |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 563)May include surrounding context.

md
|    Q2    | Step 1 表格必须紧接 Step 0,先于研发路线输出                                                                                                                                                                                                                                                             |
|    Q3    | 技术难题编号统一使用 T1、T2…TN;攻关方向统一使用方向①②③…;[S#] 全局唯一                                                                                                                                                                                                                                  |
|    Q4    | 攻关方向数量 k = min(N, max_directions),可合并同类项但不得遗漏任何难题                                                                                                                                                                                                                                  |
|    Q5    | 每路研发内容不少于 3 条,且每条至少关联 1 个 [S#] 证据                                                                                                                                                                                                                                                   |
|    Q6    | 总结表必须包含"对应难题"列,明确标注每路方向覆盖的 T# 编号                                                                                                                                                                                                                                               |
|    Q7    | 附录 A4 网络学术清单必须标注来源平台(取值范围以 [assets/workflow.md](assets/workflow.md) 平台域名对照表为准,未列入对照表的来源标"其他");条数与归并规则见 Step 3                                                                                                                                      |
|    Q8    | 未有证据支撑的结论标注 Unverified                                                                                                                                                                                                                                                                  
...[truncated 23 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 564)May include surrounding context.

md
|    Q3    | 技术难题编号统一使用 T1、T2…TN;攻关方向统一使用方向①②③…;[S#] 全局唯一                                                                                                                                                                                                                                  |
|    Q4    | 攻关方向数量 k = min(N, max_directions),可合并同类项但不得遗漏任何难题                                                                                                                                                                                                                                  |
|    Q5    | 每路研发内容不少于 3 条,且每条至少关联 1 个 [S#] 证据                                                                                                                                                                                                                                                   |
|    Q6    | 总结表必须包含"对应难题"列,明确标注每路方向覆盖的 T# 编号                                                                                                                                                                                                                                               |
|    Q7    | 附录 A4 网络学术清单必须标注来源平台(取值范围以 [assets/workflow.md](assets/workflow.md) 平台域名对照表为准,未列入对照表的来源标"其他");条数与归并规则见 Step 3                                                                                                                                      |
|    Q8    | 未有证据支撑的结论标注 Unverified                                                                                                                                                                                                                                                                        |
|    Q9    | 检索数量统计必须使用工具返回去重后的真实计数(即附录行数);禁止编造或主观估算。若工具未返回可信计数,相应单元格写"未提及",不得用占位数字凑数                                                                                                                                                           |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 565)May include surrounding context.

md
|    Q4    | 攻关方向数量 k = min(N, max_directions),可合并同类项但不得遗漏任何难题                                                                                                                                                                                                                                  |
|    Q5    | 每路研发内容不少于 3 条,且每条至少关联 1 个 [S#] 证据                                                                                                                                                                                                                                                   |
|    Q6    | 总结表必须包含"对应难题"列,明确标注每路方向覆盖的 T# 编号                                                                                                                                                                                                                                               |
|    Q7    | 附录 A4 网络学术清单必须标注来源平台(取值范围以 [assets/workflow.md](assets/workflow.md) 平台域名对照表为准,未列入对照表的来源标"其他");条数与归并规则见 Step 3                                                                                                                                      |
|    Q8    | 未有证据支撑的结论标注 Unverified                                                                                                                                                                                                                                                                        |
|    Q9    | 检索数量统计必须使用工具返回去重后的真实计数(即附录行数);禁止编造或主观估算。若工具未返回可信计数,相应单元格写"未提及",不得用占位数字凑数                                                                                                                                                           |
|   Q10    | 原文未提及的子项填"未提及",不得捏造;忠实原文不添加主观评价                                                                                                                                                                                                                                             |

Static analysis

No suspicious patterns detected.