Back to skill

Security audit

论文查重字符策略

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language guidance skill for paper-checking counts, product choice, and pricing, and it does not install code or perform uploads or payments itself.

Install this only for Chinese-language paper-checking support. Before using it for real submissions, confirm the CHECK_SITE_URL, the checking provider’s privacy terms, and all pricing on the website; do not upload sensitive papers or pay unless you trust that site.

Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (60)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file’s natural-language content is entirely in Chinese and repeatedly instructs the assistant to answer using this skill’s rules, but it does not state that Chinese is optional or that the skill is limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
This manifest allows the skill to be invoked implicitly, but the file does not define any narrow trigger phrases, exclusions, or contextual limits. That makes activation conditions ambiguous and increases the risk of unintended invocation from broadly related conversation about plagiarism checking or paper tools.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This file presents the title, description, and core flow labels in Chinese, while also including some English helper text, but it does not indicate that the skill is China-specific or that users can choose their preferred language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The title and description are presented only in Chinese, and the rest of the visible instructional text in the SVG is likewise Chinese-dominant. For a general product-selection strategy asset, this imposes a specific language without any visible user opt-in or documented locale limitation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The visible instructional text is entirely in Chinese, including the step title and submission guidance, with no indication that language choice is optional or that the asset is intended only for a Chinese-language context. This is a natural-language locale policy concern because the file presents mandatory user-facing guidance in a single language without opt-in.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
This file contains user-facing instructional text such as “进入‘审阅’选项卡” and related guidance entirely in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly documented and justified, which is not present here.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
This file contains user-facing instructional text only in Chinese, including headings, guidance, and warnings. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern when no justification or alternative is provided.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
This markdown file presents all user-facing instructions exclusively in Chinese, and it does not state that the skill is intended only for Chinese-speaking users or offer any language/locale choice. That can violate a language/locale policy when users are not given an opt-in or justified regional constraint.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
This markdown file is natural-language content, so policy checks apply. The instructions consistently force a single language/locale experience with no opt-in or alternative language path, which can violate language-choice policies when no justification is given.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
�ُ��	���B~���ICC_PROFILE�applmntrRGB XYZ �"acspAPPLAPPL���-appldescPbdscm��cprtp#wtpt�rXYZ�gXYZ�bXYZ�rTRC�
aarg� vcgt0ndin@>mmod�(vcgp�8bTRC�
gTRC�
aabg� aagg� descDisplaymluc'
hrHR�koKR
�nbNOidhuHU(csCZ<slSIRdaDK
fnlNL�fiFI�itIT�esES�roRO�frCA�ar�ukUA
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
~kdt�-~������|5�tՖsimk��iqw�-n�˕��$i-�0B����9?��QE�HU�1 6	
@=	�j��
s�i�	�+�·.����Q���"ӟ�F��[
�bm�2��i
�ĉ����n5�=⇈/�ifߣ��V�w$c2<���
�c:�
I#+���\u��W��A�麟�|Yi���0�m��-���St�3��E.�L2�=��L6��~fPEP
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
@�f���nMOM�����_2]2�������h%Y��l�>���k��������O���q!#��#��g�n��x�ĺ��5;fK�F_5�4���UAr�@U,I=I$�;�K���/��o�;�e������7���˿��/��o�Gx5	J��N�@Eܮp��
�W/�1_[۹
d6Ȳ(9*ř��pdv�Xe�nd۵��7D�����5VE�
�Ueu$0pC� �ր:�
��Z�tZ�xzV��Ԡ���л$�B�	$H���Us�с���k~1����{��6)`�;Iq,HdH�'����lv�Q@v�/�xg@}
�7�i?h�7W76��sO�	
nG#��V&��!��h���ie��8�@Y���U@�N
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
��Z�tZ�xzV��Ԡ���л$�B�	$H���Us�с���k~1����{��6)`�;Iq,HdH�'����lv�Q@v�/�xg@}
�7�i?h�7W76��sO�	
nG#��V&��!��h���ie��8�@Y���U@�N
�Kqo=��Z���M
�r#�2:�Gb�7�W�{�j�]�@7��
\�	-q,H���91��k��������wr�\꺼6�:f�Gy�
�2Wp" ��
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
nG#��V&��!��h���ie��8�@Y���U@�N
�Kqo=��Z���M
�r#�2:�Gb�7�W�{�j�]�@7��
\�	-q,H���91��k��������wr�\꺼6�:f�Gy�
�2Wp" ��
���{�ĸ���Yj�ط�'Ru�(k�8��g?����^3
rM"C
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
�Kqo=��Z���M
�r#�2:�Gb�7�W�{�j�]�@7��
\�	-q,H���91��k��������wr�\꺼6�:f�Gy�
�2Wp" ��
���{�ĸ���Yj�ط�'Ru�(k�8��g?����^3
rM"C
��F��,��ܒp*K�[��l�bx'��I�QчP�yz�d��GeW�u��鑜
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
%~����w�Jo�?�k��������������
5_��u$6<3E5ú��5�nэ��́���������5+5�4
�h�-n�}�x�J�o#���M.�c�������
Ew����|V��h��/��X����2��S:�F��@�K���ҿ9|1�.~���C�Biw��6�uyau�M7N��L%�6�7ڑ�o�Kp���CM<P���z��/���û/i��V��W��&����>p��V7
���31��g���k;��|kw�:^���;]V{���)�)lmBG"������)��ߏ�����|Z�g�	~x�=&�̃OM�9e��c��\rCo�>L�'��ǔ+��'�~$|?�?���xs\�������U�tk��R�Ku��$�7�\#�E}��F~�^	��n<-�����ߋu8,,��iV9)
$�23
{�o����_Q��o�I�
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
����w��J]bK]b�u�Ya��].
6��,gTa,����+�
�;d��q\ƽ��
����=q�%����ll'k�X�;��70�L����Q���ľ#���w�_�O,��SH
nݴ�s���:g��5�<U�[=���jWV�"���y4��/!J3� 
��(~�E���֬|Euq��DO����%���<��J�ͣyn���������A����X�����Z������q�&6%_6�k81�@<
�T^5�ޝa�[Х���\�
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
+o�������Om��}��t��>j�~
�{��r}joKփz����q�K�Ѭ3�P�m�
6�����ҡ�����$k���L���"��ci��I%�A$�G#�k�
�RT�\�� x��r]K��n�Fk�D��+��d� �$��FMc����V}s�w���rA���C$��`d��
0�
ȯS�e�j^�\�}�ٷ���[,ca[���o+�#�#�������
:]�Q��4��l�E�n?���8�wc�sZ�����j��̗�sc̚\nlp�J΢��-7×�1�
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
�3$*�]�5$��b�OS@
'���
蚿�o����
�Q/��ck�
X@�|��
����g�j�]ӵ�+�
�f�"�X��/KHF�
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
��XdC@���|7���آ����q�x��.k�A"��2A
�K�Hsm
Z�����n|?�^x��ַ�z��=�����6AR=����	�H]� �&�9��=ON�����.-o>�&x���CfE!��~ny�Rík6�}Γmu��+��G3�3�}�$`�r;��o
[�v�5��oZ�O{�—�鉧�|�*�MCV�wB�A�݈��Dס����?
�Fk˘����\�������w�'ْ(ft�\\"7@�y�˘�mV�E{r�M(��,� 3/C;K�͌���[֯\Ky�]Nꬁ��؄c�\�'�GC@���1���Y���&���l'�W��Բ��/v�smg
�þ/�6�.�q_��N�����WZ���+�=n�rǤ�����o�m��*�i��
s����RC5�%����]�����	�0���qX4z����[
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
�ݰ"�ya
rDr2}����2�g�k���[���g����a��.KE��]}�G���
oo,���X]��-�����
�P9���#��z�,amZ�N�l-�,��W[a?gbKy����bK0''=k��uO�������1�
BT1�up��i����pkޭ��q����>�V�I7�&�]z-O6eD��N���n�����S�!�[yRx
��&���+)� �A�EGE|��
����E։�u��^KҖ����!v�\�����ҹx��ĩ��&��Q���v��FgF��2n�v�
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
�ُ��	���B~���ICC_PROFILE�applmntrRGB XYZ �"acspAPPLAPPL���-appldescPbdscm��cprtp#wtpt�rXYZ�gXYZ�bXYZ�rTRC�
aarg� vcgt0ndin@>mmod�(vcgp�8bTRC�
gTRC�
aabg� aagg� descDisplaymluc'
hrHR�koKR
�nbNOidhuHU(csCZ<slSIRdaDK
fnlNL�fiFI�itIT�esES�roRO�frCA�ar�ukUA
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
Jt�(�""0GJਢ�(��(��(��(��(��(��(��(��(��(��(��(��(��(��(��P	8�j��f�c�����6�򧸷x�bF@�G�@8&��,f����+X�
��)T�V�vpn����.~P�	��i��i��S]��>#�Ϋaz|��$�I
��9U�c<�89�+��Ua:��u_W���w�ƥe	F
?{O�S�Y��`�w'�]Z��ʐ^��I$i2$�k4r
��y*Ðz_A|;��F����h�%�������6����O�&���
���
�s6�q_N������
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Static analysis

No suspicious patterns detected.