Back to skill

Security audit

Issue Reproducer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a bug-report formatter, but its bundled script contains under-disclosed local directory, CSV, pattern, and skill-audit modes that could inspect project files if activated.

Install only if you are comfortable with a local Python helper that reads user-supplied files and can write an output file. For normal use, keep resources/spec.json in structured_brief mode and avoid running it on broad directories or sensitive repositories unless you have reviewed the script and intend to use the audit/scanning behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较窄的用途:整理 bug 描述为复现信息模板。但代码实际实现了一个多模式、本地文件/目录分析工具,能力范围明显更广,且包含与 bug 复现整理无关的目录扫描、数据审计、安全模式扫描、Skill 规范检查等功能。虽然其中的 structured_brief 模式可能可用于整理 bug 描述,但这只是其中一种模式,不能代表代码的主要整体能力。代码还会读取输入路径下的文件内容、遍历目录、解析 CSV、检查项目结构,这些资源访问和能力均未在声明中体现。因此描述不能准确代表该代码块的实际行为,属于明显不匹配。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the declared purpose of a bug-reproduction skill and includes directory, CSV, pattern, and skill-repository audit behaviors. This overbroad functionality can cause unintended inspection of arbitrary local files and disclosure of sensitive project structure or contents when a user expects only benign bug-report structuring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents all user-facing instructions, usage, warnings, and examples exclusively in Chinese. Under the language/locale policy, forcing a specific language without user opt-in or documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly mentions local resources, output generation, and possible shell execution via python3 .../scripts/run.py, but it does not declare any permissions or allowed-tools scope. This creates an authority gap where the runtime may permit broader file and shell access than users or reviewers expect, increasing the chance of unintended reads, writes, or command execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The title, summary, examples, and risk text are all presented in Chinese, which effectively constrains the skill to a specific language. The file does not document that the skill is China/Chinese-specific or offer any user opt-in or alternative language choice, which may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated report strings in make_structured_report are fixed in Chinese, which forces a specific language on users. The file provides no option to select language and no justification that the skill is region-specific, so this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

directory_report, csv_report, pattern_report, parse_frontmatter error messages, and skill_audit all emit Chinese-language headings and messages. Because the script's CLI does not expose any locale selection and the file contains no documented regional limitation, it mandates a specific language across multiple execution paths.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Regex-based scanning for secrets and risky shell patterns is outside the stated workflow and encourages processing arbitrary files for sensitive content. Even though matches are partially masked in one case, the feature can still expose snippets, internal URLs, and repository contents in generated output without clear user expectation or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill-audit functionality inspects repository layout and frontmatter fields, which is unrelated to reproducing bugs and broadens the tool into a local repository analyzer. In the context of an agent skill, hidden capability expansion is dangerous because it may collect and emit metadata from directories the user did not intend to expose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description line combines Chinese and English phrasing, effectively prescribing multilingual output/interaction behavior without stating that the user can choose their preferred language. Under the language/locale policy rule, a skill should explicitly offer language choice or document a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely written in Chinese and provides no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the natural-language policy rule, this can be treated as a locale/language constraint without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire template, including the title and all section instructions, is written only in Chinese, which implies a fixed output language. Under the policy rules, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.