Back to skill

Security audit

父母的功课

Security checks for vulnerabilities and agentic risk

Overview

This parenting-support skill is mostly coherent, but it needs Review because it ships scripts that can persist sensitive family data in under-disclosed locations and can broadly commit, push, or publish local files if run with release flags.

Install only if you are comfortable with a Chinese parenting and emotional-health support skill that includes optional local scripts. Do not enable ALLOW_FILE_PERSISTENCE, ALLOW_AUTO_PUSH, or ALLOW_AUTO_PUBLISH unless you have reviewed the files that may be saved, committed, pushed, or published. Treat crisis guidance as educational support, not professional or emergency care.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/maintenance.py:49
Finding

Broad Automatic Git Staging Can Publish Sensitive Local Data

Content
View full analysis
bool: """自动提交所有变更""" if not has_changes(): print("✅ 无变更,跳过提交") return False version = get_version() summary = f"auto: v{version} 定时维护" run(["git", "add", "-A"]) run(["git", "commit", "-m", summary, "--allow-empty"]) print(f"📦 已提交: {summary}") return True def auto_push() -> bool: """推送到 GitHub""" if not os.environ.get("ALLOW_AUTO_PUSH"): print("⏭️ 跳过推送 (设置 ALLOW_AUTO_PUSH=1 以启用)") return False r = run(["git", "push", "origin", "master", "--no-verify"], check=False) if r.returncode == 0: print(f"🚀 已推送到 GitHub") return True else: print(f"⚠️ 推送失败: {r.stderr[:200]}") return False def auto_publish(): """发布到 ClawHub""" if not os.environ.get("ALLOW_AUTO_PUBLISH"): print("⏭️ 跳过 ClawHub 发布 (设置 ALLOW_AUTO_PUBLISH=1 以启用)") return False version = get_version() today = datetime.now().strftime("%Y-%m-%d") r = run(["clawhub", "publish", ".", "--slug", "fu-mu-gong-ke", "--name", "父母的功课", "--version", version, "--changelog", f"auto: v{version} ({today})"], check=False) ``` ```python committed = auto_commit() if not committed: return auto_push() auto_publish() ``` ### Technical Analysis The maintenance workflow executes `git add -A`, which stages every modified, deleted, and untracked file under the repository rather than restricting staging to an approved source-file allowlist. It then commits the complete staged set without presenting the staged file list for approval. When `ALLOW_AUTO_PUSH` is set, the resulting commit is pushed to the configured `origin` remote. When `ALLOW_AUTO_PUBLISH` is set, the ...[truncated 2739 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/fu-mu-gong-ke/SKILL.md:5
Finding

Packaged Skill Manifest Incorrectly Denies File Persistence

Content
View full analysis
List[Dict[str, Any]]: f = DATA_DIR / "assessment_history.json" if not f.exists(): return [] try: with open(f) as fp: return json.load(fp) except json.JSONDecodeError: return [] except IOError: return [] def save_history(history: List[Dict[str, Any]]) -> None: try: with open(DATA_DIR / "assessment_history.json", "w") as f: json.dump(history, f, ensure_ascii=False, indent=2) except IOError as e: print(f"警告:保存历史记录失败: {e}") ``` Assessment results are added to the persistent history: ```python if result: history = load_history() if isinstance(result, list): history.extend(result) else: history.append(result) save_history(history) print(f"\n已保存到历史记录 (共{len(history)}条)") ``` The system integrator separately implements conversation-state persistence: ```python def save(self, path=None): save_path = path or (DATA_DIR / f"state_{self.session_id}.json") try: with open(save_path, "w", encoding="utf-8") as fh: fh.write(js ...[truncated 3682 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (252)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog documents a maintenance script that can automatically check changes, commit, push, and publish, which expands the skill from local dialogue support into repository/network-affecting automation. Even if gated by environment variables, this kind of capability is dangerous in a skill context because it can cause unintended external actions, leak content to remotes, or modify release state without strong user confirmation and scope controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the actual tool is historical data visualization reading from a user-home path and exposing undocumented CLI triggers, that is a meaningful mismatch from a dialogue-support skill. Undeclared interfaces and storage locations increase the chance of accidental data exposure, unauthorized invocation, or operation outside expected policy boundaries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The audit records a direct contradiction between the skill's stated behavior ('no file writes/persistence') and reported script behavior writing local history under a user directory. In a parenting/mental-health support context, undisclosed storage of sensitive emotional or family data creates a meaningful privacy and trust risk even if data is only local.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document states the skill should stop analysis during crisis situations, yet it reportedly continues analytical dialogue for self-harm or suicide scenarios. In a high-risk emotional support skill, that inconsistency can delay escalation to emergency resources, increase unsafe advice exposure, and worsen outcomes for a user in acute crisis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script can push repository contents to GitHub and publish the skill externally to ClawHub, which contradicts the skill description claiming local-only data storage and no external transmission. If local session history, evaluation artifacts, or other sensitive files are present in the repository tree, running this maintenance flow could exfiltrate private data to external services once the environment flags are enabled.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Writing data to ~/.hermes/still_growing/ instead of the declared SKILL_DIR/data location expands the storage scope beyond what users and reviewers were told to expect. This is dangerous because it hides where sensitive records live, complicates auditing and deletion, and increases the chance that private parenting or emotional-support data persists across sessions without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The audit records a direct contradiction between the skill's declared behavior and its actual local file writes. In a parenting/mental-health support context, silently persisting sensitive conversation-derived data creates a meaningful privacy and trust risk because users may disclose intimate family, emotional, or child-related details under the assumption that nothing is stored.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The audit identifies a contradiction in suicide/self-harm handling: policy says to stop analysis immediately, but the actual flow continues analytical dialogue. In a crisis-support-adjacent parenting skill, this is especially dangerous because continued analysis can delay urgent escalation, provide inappropriate responses to a person in acute distress, and materially increase risk of harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module generates user-facing escalation guidance for scenes that include suicide and self-harm indicators, but it does not attach any crisis warning, emergency referral, or instruction to seek immediate qualified help. In a parenting mental-health support skill, this is especially dangerous because users may rely on the generated hint as sufficient guidance during a crisis, delaying urgent intervention.

Content

No source excerpt is available for this finding.

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/test_reasoning_engine.py (reported line 153)May include surrounding context.

python
self.assessor.assess("我很焦虑", crisis)
        self.assertEqual(result.level, EmotionLevel.BLACK)

    def test_response_depth_mapping(self):
        result = self.assessor.assess("崩溃了")
        self.assertEqual(result.response_depth, ResponseDepth.CRISIS)


class TestScenarioMatcher(unittest.TestCase):
    def setUp(self):
        self.matcher = ScenarioMatcher()

    def test_score_drop(self):
        result = self.matcher.match("孩子成绩下降了,考试不及格")
        self.assertIsNotNone(result)
        self.assertEqual(result.name, "孩子成绩下降")

    def test_school_refusal(self):
        result = self.matcher.match("孩子不想去学校,厌学")
        self.assertIsNotNone(result)
        self.assertEqual(result.name, "孩子不想上学")

    def test_phone_addiction(self):
        result = self.matcher.match("孩子沉迷游戏,天天玩手机")
        self.assertIsNotNone(result)
        self.assertEqual(result.name, "孩子沉迷手机游

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skills/fu-mu-gong-ke/scripts/test_reasoning_engine.py (reported line 153)May include surrounding context.

python
self.assessor.assess("我很焦虑", crisis)
        self.assertEqual(result.level, EmotionLevel.BLACK)

    def test_response_depth_mapping(self):
        result = self.assessor.assess("崩溃了")
        self.assertEqual(result.response_depth, ResponseDepth.CRISIS)


class TestScenarioMatcher(unittest.TestCase):
    def setUp(self):
        self.matcher = ScenarioMatcher()

    def test_score_drop(self):
        result = self.matcher.match("孩子成绩下降了,考试不及格")
        self.assertIsNotNone(result)
        self.assertEqual(result.name, "孩子成绩下降")

    def test_school_refusal(self):
        result = self.matcher.match("孩子不想去学校,厌学")
        self.assertIsNotNone(result)
        self.assertEqual(result.name, "孩子不想上学")

    def test_phone_addiction(self):
        result = self.matcher.match("孩子沉迷游戏,天天玩手机")
        self.assertIsNotNone(result)
        self.assertEqual(result.name, "孩子沉迷手机游

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section gives detailed suicide/NSSI risk-assessment, safety-planning, and means-restriction guidance to parents without a clear, prominent statement that the material is educational only and not a substitute for emergency or professional crisis care. In a high-risk mental health context, users may rely on the skill instead of seeking urgent help, causing delayed intervention, unsafe home management of an acute crisis, or false reassurance.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill discusses a child saying 'I don't want to live' and advises immediate care, but it does not clearly and prominently state that the skill is not emergency, crisis, or medical care. In a high-risk parenting and suicidality context, users may over-rely on the conversational framework instead of seeking urgent professional intervention, causing dangerous delay during a crisis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatic commit/push/publish behavior is externally visible and potentially destructive, yet the changelog excerpt does not communicate concrete warnings, consent requirements, or failure modes. In a skill intended for sensitive parenting support, hidden or under-warned automation increases the risk of accidental disclosure of repositories, dialogue artifacts, or other local content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The changelog claims prior persistence features were removed because they conflicted with the manifest, yet other entries still describe insight capture, local statistics, reporting, and stored session-related data. This inconsistency is a real security and privacy issue because users and reviewers may rely on the manifest's promises while the skill still retains sensitive parenting dialogue data locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog describes automatic capture and persistence of conversation insights without a clear privacy warning, despite the skill handling highly sensitive parenting and mental-health-adjacent content. Even local-only storage can expose private family information through device compromise, backups, logs, or later unintended publication/analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

L070 says '默认输出刺穿句', and the surrounding changelog content is entirely in Chinese, describing the skill's default response behavior rather than a region-specific tool constraint. This suggests the skill may force a language/locale-specific output style without documenting user choice or opt-in, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is written entirely in Chinese and all required example prompts, workflow labels, and response scripts are Chinese-only. The file does not indicate that Chinese is optional, user-selectable, or justified as a region-specific tool, so it appears to impose a specific language/locale by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.