Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md | 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |
Security audit
Security checks for vulnerabilities and agentic risk
This is a plain summarization guidance skill with no executable code, network behavior, persistence, or hidden high-impact actions.
Install only if you want a general summarization formatter. Be aware that it may be invoked broadly for summarization-like tasks, and review the license text because the documentation is not offered under the same MIT terms implied by some metadata.
Referenced artifact was not completely inspected
| 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |
The description uses broad everyday examples like meeting notes, comparison tables, and timelines, which are common requests across many workflows. If the platform uses description text for discovery or invocation, this broad phrasing can make the skill match too many unrelated tasks, increasing accidental activation and misrouting risk.
The trigger keywords include very generic terms such as "summarize" and "pro", which can cause the skill to activate in unrelated conversations. Over-broad activation increases the chance of unintended routing, where the agent applies this skill when the user did not explicitly request it, potentially overriding more appropriate behaviors or causing unnecessary processing of sensitive text.
This file includes binding licensing and scope language in Chinese while the main license body is in English, but it does not provide an explicit language/locale choice or explain why users must rely on a Chinese-only notice for key terms. Under the policy, forcing a specific language for essential instructions without opt-in or justification is a natural-language locale concern.
No suspicious patterns detected.