Back to skill

Security audit

卧室装修避坑指南

Security checks for vulnerabilities and agentic risk

Overview

This is a passive bedroom-renovation advice skill, but its reference corpus is overbroad and repeatedly includes promotional contact prompts and real-estate advice outside the declared bedroom scope.

Install only if you are comfortable with a renovation-advice skill whose source corpus needs cleanup. It does not run code or access accounts, but users should treat its non-bedroom topics, promotional contact snippets, and home-buying claims as unvetted source material rather than authoritative guidance.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The references contain explicit lead-generation and contact prompts such as hotline/WeChat/'read original'. In an assistant skill, this can steer users off-platform, undermine platform safety controls, and enable covert promotion or social-engineering-style redirection unrelated to the user’s request.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill’s own guidance says external-platform and WeChat lead-gen content must not appear, yet the bundled references retain large amounts of exactly that material. This contradiction makes policy bypass likely during generation and increases the chance the model reproduces prohibited outreach content despite local rules.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
This section again embeds lead-generation text while the role specification explicitly forbids such content. Because the skill mixes normative instructions with contradictory examples, the assistant may imitate the unsafe examples, causing repeated off-platform redirection and policy noncompliance.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The Q&A guidance forbids sharing contact methods, but the same file continuously embeds them. In skill contexts, this is dangerous because retrieval may surface those lines directly, causing the assistant to advertise or route users to external channels under the guise of advice.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The reference bundle is supposed to support a bedroom-decoration skill, but it includes extensive unrelated content on kitchens, bathrooms, balconies, living rooms, home-buying, whole-home customization, and renovation strategy. This scope creep can cause the agent to answer outside its declared domain, increasing the chance of unsafe, irrelevant, or policy-misaligned guidance being surfaced to users.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The file contains real-estate purchasing and location-selection advice that is unrelated to bedroom renovation. In a bedroom-focused skill, this broadens the model’s effective authority into financial and safety-sensitive property decisions without justification, which can mislead users and bypass expected domain boundaries.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The skill bundle includes broad smart-home and surveillance recommendations that exceed a bedroom-decoration scope. While not overtly malicious, this can steer the agent into advising on security devices and whole-home automation without the user expecting that expansion, creating unnecessary privacy and safety risk surface.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
## 第八、磁吸广告框做装饰画。


  A3放正本 A4放副本\n营业执照\n营业执照证书\nTHORIZATION\n专利证书\n新城\n城\n授权\n工长.com(贵阳)\n伙伴\n李wang\n新汇\n105日\n107805858058405405500540550054050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050050\n\n


记得买哑光面的效果更好,大的尺寸是a3,小的是a4,加起来才六块钱,还有好多颜色的边框可以选。搜营业执照磁吸展示相框,找一家便宜的就行。
Confidence
92% confidence
Finding
The file contains clear context-window stuffing/noise with long low-value repeated numeric sequences embedded in content. Excessive irrelevant tokens can dilute retrieval quality, increase prompt budget consumption, and crowd out higher-value instructions or safety constraints, making the skill less reliable and easier to steer with junk context.

Static analysis

No suspicious patterns detected.