Back to skill

Security audit

Skill Routing Benchmark

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local, review-oriented routing benchmark helper with disclosed Python execution and no evidence of network access, credential use, persistence, or destructive behavior.

Install only if you are comfortable with a Chinese-language local helper that may read the input file you provide and can write a report to a path you specify. Avoid pointing it at broad private directories or sensitive unredacted materials unless you intentionally want them summarized or audited locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明聚焦于“路由冲突测试、生成正例/反例/负向触发语句”,但代码中没有任何与 skill 路由冲突判定、相似度比较、触发语句生成、benchmark 样本构造直接相关的逻辑。相反,代码实现的是一个通用报告引擎:读取 resources/spec.json,按 mode 执行 structured_brief、directory_audit、csv_audit、pattern_audit、skill_audit 等任务,处理目录、CSV、Markdown、源码和 Skill 目录结构,并输出审计报告。这属于 materially different primary purpose,且具备多项未声明能力。尽管其中有 skill_audit 分支与 Skill 相关,但其行为是检查文件完整性与元数据,而不是路由冲突测试。因此描述与实际行为明显不符。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script implements directory auditing, pattern scanning, CSV inspection, and skill-package compliance checks that materially exceed the stated routing-benchmark purpose in the manifest. This kind of undeclared capability increases the risk of unauthorized local content inspection and creates a deceptive trust boundary for users who expect only benchmark generation behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The regex engine searches user-specified files and directories for secrets, private URLs, and dangerous command patterns, which is a security-scanning capability unrelated to the declared routing-benchmark scope. In this context, the mismatch is dangerous because it enables broad inspection of local content and surfaces sensitive snippets while users may not realize the skill performs security reconnaissance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill title and the entire README content are presented in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese throughout, including the title, evaluation table, and audit conclusion, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable capabilities indirectly via metadata and instructions to run python3, but it does not define an explicit tool scope such as allowed tools or permissions. This creates ambiguity about what the skill may access or modify, increasing the chance that a caller or runtime grants broader file and shell access than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description and core instructions are primarily written in Chinese, with no statement that the skill can operate in other languages or adapt to the user's preferred locale. This can violate language/locale policy when a skill effectively constrains interaction language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest presents core user-facing content entirely in Chinese, while also including an English example phrase, but it does not state that the skill is Chinese-only or offer any language/locale selection. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains multiple fixed Chinese user-facing strings in generated reports, such as headings and guidance text. Under the natural-language policy rule, forcing a specific language without user opt-in is a policy violation because the user is not given any locale selection or indication that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several other report functions emit fixed Chinese headings and instructions, including directory, CSV, and pattern audit reports. Because the script consistently enforces one language across user-visible output and does not offer a choice, this violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill_audit path inspects package structure, parses SKILL.md frontmatter, and reports compliance status for multiple repository files despite the manifest describing a routing benchmark tool. This hidden package-inspection capability broadens the skill’s access to repository contents and may expose internal metadata or create misleading expectations about what the tool will analyze.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The frontmatter validation and skill-audit functions return Chinese-language error and status text, again without any documented locale restriction or user opt-in. This is a policy issue in natural-language content regardless of file type because it constrains the user experience to a single language by implementation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script can write generated output to an arbitrary user-supplied path, but this file-writing behavior is not reflected in the skill’s limited benchmark/routing description. Undisclosed write capability can be abused to overwrite local files in expected execution contexts or to persist scanned content into unintended locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is entirely written in Chinese, including headings, instructions, and expected outputs, with no indication that the user can choose another language or locale. This can violate a language/locale policy when a skill implicitly requires a specific language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown content is entirely written in Chinese and instructs the skill behavior in that language, without indicating that users may choose another language or locale. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing headings and instructions exclusively in Chinese, including the title and workflow guidance. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown template is entirely written in Chinese and instructs users to fill the output structure in that language, but it does not offer a language choice or explain a justified region-specific requirement. That creates a natural-language locale policy concern because the skill appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The argparse description presents the program generically as a local support script for the skill, while the actual implementation contains several substantive audit modes including directory, CSV, pattern, and skill-package analysis. This documentation understates and mischaracterizes the tool’s intent compared with what the code actually does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.