Back to skill

Security audit

卫生间装修避坑指南

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only renovation advice skill, but its bathroom-focused description is broader in practice and includes unrelated home-buying, contract, shopping, regional, and contact-promotion material.

Install only if you want a broad Chinese-language Xi'an-style renovation knowledge base, not a tightly limited bathroom guide. Treat any home-buying, contract, budget, brand, or regional code advice as informal opinion and independently verify it locally; ignore any WeChat, hotline, shopping, or public-account prompts that may leak from the source material.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is scoped as a bathroom renovation pitfall guide, but the embedded corpus spans kitchens, bedrooms, whole-home renovation, budgeting, contractor selection, appliances, and home-buying. This scope creep creates an over-privileged advisory surface: a user invoking a narrowly themed skill can be steered into unrelated high-stakes decisions, increasing the chance of misleading or manipulative outputs outside the advertised competence boundary.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Embedding buy/house-selection guidance inside a bathroom-focused skill lets the agent influence financially significant purchase decisions that users would not reasonably expect from this tool. In skill ecosystems, hidden expansion into adjacent decision domains is dangerous because it bypasses user intent and trust boundaries while appearing authoritative.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill includes contractor selection, contract review, budget auditing, and construction-team evaluation capabilities, which are materially broader than bathroom renovation pitfalls. This can nudge users into relying on the skill for contractual and financial judgments without clear consent, increasing risk of harmful or biased recommendations.

Intent-Code Divergence

High
Confidence
94% confidence
Finding
The skill’s policy says not to recommend brands, merchants, or companies, yet the corpus repeatedly names and endorses specific brands. This internal contradiction can cause policy bypass at generation time, enabling covert commercial steering or undisclosed affiliate-style promotion under the guise of neutral advice.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The answer rules prohibit IMA/WeChat/Xiaohongshu/public-account style platform references, but the knowledge base and embedded instructions repeatedly include those channels and contact prompts. That makes prompt/policy collision likely and can turn the skill into a lead-generation or off-platform redirection mechanism.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The reference bundle materially exceeds the skill’s declared bathroom-renovation scope and includes unrelated guidance on contractor selection, contracts, property buying, old-house renovation, and whole-home budgeting. In an agent setting, this creates instruction-scope drift: the model may answer outside its intended domain, give higher-risk financial/contract advice, or act on irrelevant content that the user did not ask for.

Description-Behavior Mismatch

Low
Confidence
89% confidence
Finding
The embedded promotional/contact language introduces off-platform lead-generation behavior into a skill that is supposed to provide renovation guidance. Even if not directly malicious, it can steer responses toward solicitation, weaken user trust, and cause the agent to prioritize conversion content over task-relevant advice.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The knowledge base explicitly contains shopping prompts, star/follow prompts, and direct contact-conversion language. In an agent context, this can cause unauthorized marketing behavior, off-platform redirection, or recommendations that are not aligned with the user’s request, especially if the model treats these embedded instructions as actionable guidance.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill hardcodes a Xi'an-localized perspective and source selection without requiring user opt-in, which can produce advice mismatched to other regions' codes, construction norms, climate, and property-management rules. In safety-relevant home-renovation guidance, silent regional assumptions increase the chance of incorrect recommendations being applied elsewhere.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
## 第八、磁吸广告框做装饰画。


  A3放正本 A4放副本\n营业执照\n营业执照证书\nTHORIZATION\n专利证书\n新城\n城\n授权\n工长.com(贵阳)\n伙伴\n李wang\n新汇\n105日\n107805858058405405500540550054050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050\n\n


记得买哑光面的效果更好,大的尺寸是a3,小的是a4,加起来才六块钱,还有好多颜色的边框可以选。搜营业执照磁吸展示相框,找一家便宜的就行。
Confidence
86% confidence
Finding
The file contains obvious context-window stuffing/noise, including long low-value repetitive numeric text and bulky irrelevant material. This degrades model attention, increases prompt-collision risk, and can hide policy-violating or manipulative content inside a large corpus, making reliable safety enforcement harder.

Static analysis

No suspicious patterns detected.