Back to skill

Security audit

how-to-run-meetings

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language meeting-methodology skill made of static documentation, with no code execution, credential access, persistence, or hidden data flow found.

This skill appears safe to install from a security perspective. Users should know it is mainly Chinese-language, book-derived meeting guidance with a party/government meeting context, so adapt it for business, legal, confidential, or formal governance settings rather than treating it as binding procedure.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation condition is extremely broad: it claims applicability to nearly any meeting-related task, from planning and speaking to follow-up and rules. In an agentic system, this can cause the skill to be invoked in contexts where narrower, more appropriate, or policy-constrained skills should apply, increasing the risk of irrelevant guidance, prompt-scope capture, or inappropriate influence over sensitive organizational workflows.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This markdown file presents all instructional content in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. The policy requires avoiding forced language or locale constraints unless there is user opt-in or a clearly justified regional scope.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The entire skill content is written in Chinese and does not provide any indication that users may choose another language or that the Chinese-only presentation is required for a region-specific or compliance-related purpose. Under the stated policy, a fixed language without user opt-in can constitute a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The entire skill content is written only in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. Under the policy rule for language or locale constraints, forcing a single language without opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The entire skill content is written in Chinese and provides no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The document declares `lang="zh-CN"`, and the visible content is entirely in Chinese, which indicates a fixed language/locale choice. Under the policy rule, this is a natural-language locale constraint that is not presented as optional or justified as region-specific.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This markdown file contains natural-language instructions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The skill description is presented entirely in Chinese and frames the skill around a Chinese-language book-derived methodology without offering an alternative language or stating that the user can choose their preferred language. Under the policy rule, a forced language or locale without user opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
72% confidence
Finding
The manifest description presents the skill in Chinese and then appends English guidance, but it does not state whether the skill should respond in Chinese, English, or match the user's preference. This can create a language-policy issue if the skill implicitly forces or defaults to a language without user opt-in.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This markdown file presents all instructions and content exclusively in Chinese, with no indication that users may choose another language or that the content is intentionally limited to a Chinese-speaking context.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file presents all instructional content in a single language and does not indicate that the user opted into Chinese or that the skill is intended only for a Chinese-speaking audience. Under the language/locale policy criterion, forcing one language without opt-in can be a natural-language policy issue.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
This markdown file contains only Chinese-language instructional content and does not indicate that the skill is intended specifically for Chinese-speaking users or provide any opt-in for language preference. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The entire skill content is presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy for natural-language constraints, a fixed language without opt-in or justification is a locale/language policy concern.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
This markdown file contains user-facing natural language exclusively in Chinese, beginning with the title at L01 and continuing throughout the glossary entries. Under the policy, forcing a specific language without user opt-in can be a language/locale policy violation when no explicit justification or alternative is provided.

Static analysis

No suspicious patterns detected.