Back to skill

Security audit

Local Rag Index Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a local planning skill that generates reviewable knowledge-indexing guidance, with no evidence of network access, persistence, or destructive behavior.

Install this if you want a Chinese-language helper for planning local knowledge indexes and producing reviewable Markdown briefs. Keep input paths limited to material you intend to summarize; avoid pointing it at broad private directories unless you have reviewed the script and configuration. The extra inactive audit code is not harmful in the shipped setup, but it is worth being aware of before modifying resources/spec.json.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述强调的是“规划本地知识库/RAG 的组织方式与访问边界”的咨询/设计用途。但实际代码并不实现知识库目录规划、分片策略设计、命名规范制定、更新时间策略或访问边界建模等专门功能。相反,它是一个通用报告生成与审计工具:可扫描目录中文本文件、统计扩展名、抽取 Markdown 标题、分析 CSV 字段、匹配危险 shell/secret/private URL 模式,以及检查 Skill 目录文件完整性与 SKILL.md frontmatter。这些能力明显超出且偏离了声明中的主要目的,属于未声明的审计/安全扫描/规范检查能力。虽然都与“知识工作流”有些间接关联,但主功能和能力边界已发生实质性偏移,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger examples are generic conversational phrases that can match normal user requests unrelated to this specific skill, increasing the chance of accidental routing or over-invocation. In a skill that shapes knowledge-indexing plans and explicitly mentions ignoring permission isolation in metadata, broad triggers can cause the agent to apply this skill in contexts where access-boundary handling is ambiguous or inappropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all user-facing content in a single language and does not indicate that Chinese is optional or required for a region-specific purpose. Under the policy for natural-language constraints, forcing one language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises executable capabilities via python3 and implies file input/output behavior, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where a host or reviewer cannot clearly enforce least privilege, increasing the chance the skill is granted broader file and shell access than its planning-only purpose requires.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the main skill title/instructions are written in Chinese and present the skill behavior as Chinese-first, with no indication that users may choose another language. This creates a language/locale policy concern because the skill appears to impose a specific language without opt-in or an explicit region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The heading and all instructions in this example input are written only in Chinese, which indicates a fixed language expectation without offering the user a language choice. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown example output forces a specific language/locale through all headings and instructional text, but does not indicate that Chinese is optional or that the skill is intended only for Chinese-speaking users. Under the policy, language constraints should either be opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title, category label, summary, and input hint are written in Chinese, indicating a fixed language/locale for the skill's user-facing experience. The file does not mention any user opt-in, language selection, or region-specific justification, which can violate language-choice policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated report strings in make_structured_report are written exclusively in Chinese, and similar hard-coded Chinese output appears throughout other report functions. This forces a specific language for user-facing output without any opt-in, locale selection, or justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script includes a generic pattern-scanning capability over arbitrary files and directories, including checks for secrets, dangerous shell commands, and private URLs, which exceeds the declared scope of a local RAG index planning skill. In a skill ecosystem, this kind of scope expansion is dangerous because it can silently inspect unrelated local content and surface sensitive snippets, creating an unnecessary data-exposure and trust-boundary violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill can audit arbitrary skill-package contents, file completeness, and frontmatter metadata, which is unrelated to the stated purpose of planning a local knowledge-base index. This broadens the tool into a generic package inspector, increasing the chance of unauthorized analysis of unrelated repositories and leaking internal project structure or metadata outside the expected task boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire smoke test is written only in Chinese, including the title, instructions, and acceptance criteria. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill content is entirely presented in Chinese, and there is no statement that the skill supports multiple languages or that Chinese is a deliberate, region-specific requirement. This can amount to a language-policy issue if users are implicitly forced into one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template headings and instructions are entirely in Chinese, which implies the skill output is expected in a specific language. Under the policy rule, forcing a language or locale without offering the user a choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.