Back to skill

Security audit

Test Curl 2

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed parenting and emotional-support skill with no included executable code, networking, credential access, or hidden persistence.

Before installing, understand that this skill may respond to broad emotional distress with parenting or psychology framing. It is best used for parent-child, family, and caregiving conversations, and users should rely on professional or emergency services for crisis, legal, medical, or abuse situations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad distress phrases such as '帮帮我', '我不知道怎么办', '我崩溃了', and '我撑不住了', which are common in many non-parenting contexts. This can cause the skill to activate outside its intended scope, leading the assistant to inject parenting/psychology framing into unrelated conversations and potentially mishandle sensitive situations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The mapping states whatIsThis(input) applies to '任何用户输入' ('any user input'), which makes the skill's scope effectively universal at the routing layer. In a psychology-adjacent skill, ambiguous boundaries are risky because unrelated user content may be classified, reframed, or intercepted by this skill before a more appropriate domain-specific handler responds.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.