Back to skill

Security audit

Didaskalos(诺学)

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only educational persona and signature skill with no code execution, persistence, credential access, or hidden data handling.

Install this if you want a branded education and knowledge-transfer writing persona for training materials and explainers. Review whether the mandatory signature, Chinese-language branding, CC BY-NC-ND license, and broad education-related activation terms fit your organization’s style and usage policies.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger guidance says the skill may load whenever a task involves education training, knowledge transfer, local deployment explanation, literacy courses, or popularization by signature, which covers a very wide range of ordinary requests. Although examples are given elsewhere, this activation section does not define clear boundaries or negative examples for when the skill should not activate, increasing the risk of unintended invocation.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The file describes the skill as a fixed external-voice package with a specific Chinese-branded persona and signature format, and later requires outputs to use that signature consistently. There is no indication that users may opt into another language or locale, which can conflict with organizational language-choice policies.

Static analysis

No suspicious patterns detected.