Back to skill

Security audit

行业分析·HTML 渲染

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently renders a Chinese industry-analysis report into an HTML file and updates local workflow status, with no evidence of hidden execution, exfiltration, or persistence beyond that task.

Install this if you want a Chinese-language industry-analysis HTML renderer. Before running it, check whether output/{industry-slug}/industry-analysis-report.html or session.json already contains work you need to preserve, because the skill expects to write the HTML report and update workflow status.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to write industry-analysis-report.html and update session.json without any requirement for user confirmation or a clear warning that local files and state will be modified. In an agent environment, silent filesystem writes can overwrite prior outputs or alter workflow state unexpectedly, which is a real safety issue even though the intended use here appears operational rather than malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill hard-codes a Chinese visual/output preference (中文) when calling the downstream renderer, without indicating that this should be based on user preference or source language. This can cause undesired or misleading output for users expecting another language, reducing transparency and potentially causing downstream business communication errors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This reference file presents all instructions, labels, and guidance in Chinese only, and does not indicate that the user can select another language or that the skill is intentionally limited to a Chinese-language workflow. That can violate language/locale policy when users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.