Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md | 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |
Security audit
Security checks for vulnerabilities and agentic risk
This is a documentation-only task-management skill with no executable code, network behavior, credential handling, or persistence beyond normal task-list concepts.
Before installing, treat this as a lightweight task-management prompt, not a full storage system. Be aware that its licensing terms are confusing and that broad trigger words may invoke it in generic task discussions.
Referenced artifact was not completely inspected
| 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |
Line L009 states licensing information as "代码(.py 文件)MIT;本 SKILL.md 与其中理论文本不在 MIT 覆盖范围内" and the document is predominantly Chinese despite multiple languages being declared, which may indicate a default language constraint. Because the file does not explicitly offer a user language choice in the natural-language instructions, this can conflict with language/locale choice policy expectations.
The trigger keywords are very generic (for example, 'todo', 'tracker', and common task-management terms) and there are no activation constraints or disambiguation rules. This can cause unintended invocation in unrelated conversations, leading the agent to apply this skill out of context and potentially override better-matched instructions or user intent.
The file begins with binding policy-style licensing scope language written in Chinese, while the rest of the license text is in English. This creates a language/locale constraint for understanding the operative scope notice without any user opt-in or documented justification for restricting that instruction to Chinese.
No suspicious patterns detected.