Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md and GitHub publication should assume anyone can read `SKILL.md`.
Security audit
Security checks for vulnerabilities and agentic risk
This looks like an instruction-only Chinese lesson skill, but it is incomplete because it advertises bundled lesson and prompt assets that are not actually included.
Review this before installing and ask the publisher to either include the missing course-data and system-prompts assets or revise the skill so it no longer claims they are bundled. Do not allow repository commands or Drive sync unless the exact command is shown, the source repo documents it, and you intentionally provide the local mount path.
Referenced artifact was not completely inspected
and GitHub publication should assume anyone can read `SKILL.md`.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- absolute local paths from macOS, Linux, or Windows home directories
- loopback or debugging endpoints such as `localhost`, `127.0.0.1`, `ws://`,
`wss://`, or `devtools/browser`
- secret-shaped strings such as API keys, GitHub personal access tokens, or
inline passwords
- known Drive file IDs copied from the project manifests
- drift between the public skill copy and the bundled plugin copy
The natural-language metadata repeatedly frames the skill as specifically for Chinese lesson operations (e.g. "Chinese Laoshi Ops" and "Use Chinese Laoshi Ops"), which signals a fixed language/locale expectation. The file does not mention user choice, opt-in, or a documented region-specific justification, so this appears to violate the language/locale policy constraint.
No suspicious patterns detected.