Back to skill

Security audit

Skill Example Synthesizer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local, review-oriented example generator with some under-documented dormant audit code, but no evidence of deception, exfiltration, persistence, or destructive behavior.

This appears reasonable to install for Chinese-language skill documentation/example drafting. Treat its output as a draft, avoid using sensitive input unless you are comfortable seeing snippets in the generated report, and be aware that the bundled script contains broader audit helpers that are not part of the default packaged mode.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

描述聚焦于“为 Skill 生成正例、反例和边界例”,这是一个示例生成/路由优化用途。但代码并未体现任何专门的示例构造、分类、正反例推导或边界案例生成逻辑。相反,它从 resources/spec.json 读取配置后,根据 mode 执行多种审计类任务:structured_brief 只是把输入整理成分节摘要;directory_audit 扫描目录和 Markdown 标题;csv_audit 统计字段非空与唯一值;pattern_audit 搜索 curl|bash、rm -rf、secret 等风险模式;skill_audit 检查 Skill 文件完整性和 SKILL.md frontmatter。其核心行为是本地内容扫描、审计和报告输出,属于通用分析/合规检查工具,与声明的主要用途存在实质偏差。虽然“提升可理解性”与生成报告有轻微关联,但不足以覆盖这些实际能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a tool focused on producing high-quality examples to improve routing and understandability, but the dispatcher supports multiple unrelated audit modes including directory scanning, CSV analysis, regex-based pattern scanning, and skill structure auditing. These are not obvious implementation details of example synthesis; they materially expand the skill into a general local auditing/reporting utility.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user-facing documentation in this file is Chinese, and there is no indication that users may choose another language or that the skill is intended only for a Chinese-language environment. This can violate language or locale policy when a skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger examples are short and generic, such as asking to generate better examples or cover positive/negative cases, without tying invocation to this specific skill's documented scope. In agentic routing systems, broad triggers can cause unintended activation on unrelated requests, leading to confusing behavior, unnecessary processing, or misuse of the skill in contexts where its assumptions do not hold.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, including the title, audit table, scoring, and conclusion. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in can be a policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill advertises executable behavior via python3 and references reading templates/specs and writing output, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization and review gap: a caller or runtime may grant broader file and shell access than users expect, increasing the chance of unintended command execution or filesystem modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill title and core behavioral instructions are written as if the skill operates in Chinese by default, and the manifest description on L04 is also primarily Chinese. There is no explicit statement that users may choose another language or that output language should follow user preference, which can violate a language/locale policy requiring opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all headings and instructions in Chinese, which can force a specific language on users without any visible opt-in or justification. The policy for natural-language violations applies to all file types, and there is no indication that this is a region-specific or user-selected locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title, category label, summary, and input hint are all presented in Chinese, and the file does not indicate that the skill is region-specific or offers a language choice. This creates a natural-language policy concern because the skill appears to enforce a locale/language preference implicitly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script accepts arbitrary user-supplied paths and recursively enumerates and reads text-like files under them, which can expose sensitive local content when run in a privileged environment. Although there is no network exfiltration in this file, the generated report can still surface secrets, internal paths, headings, and file metadata to downstream consumers or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated report strings are hard-coded in Chinese, including headings, prompts, and next-step guidance. This imposes a specific language on all users without offering a language choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code defines and executes security-oriented pattern detection for shell execution chains, dangerous deletion commands, secret-like strings, and private URLs. That behavior is semantically different from generating exemplar inputs/outputs for routing, and instead acts as a lightweight security scanner.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill_audit function checks repository layout, required files, and SKILL.md frontmatter/metadata formatting. This is a compliance/validation function for skill packages, not generation of positive, negative, or boundary examples.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown content is entirely written in Chinese and specifies expected output section names in Chinese, which implies a fixed language requirement for using or validating the skill. Under the policy, forcing a specific language without user opt-in or a clearly documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.