Back to skill

Security audit

Code Review Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a code-review helper, but its paid “full implementation” claims are not supported by the incomplete and malformed artifact.

Review this carefully before installing, especially if you would rely on it for PR gates, CI blocking, paid security review, or audit decisions. It does not show malicious system access, but its advertised coverage and premium claims are not backed by the artifact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description says this is a premium package with enterprise support, but the skill metadata describes a code-review capability. This mismatch can mislead users, reviewers, or marketplaces about the skill’s actual purpose, increasing the risk of deceptive installation, policy evasion, or trust abuse in a security-sensitive tool category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises a four-perspective review with severity and remediation, but only the SECURITY path performs substantive checks; PERFORMANCE, CORRECTNESS, and STYLE are stubs. This can mislead users into trusting incomplete reviews, causing important defects to be missed in CI, PR gating, or security audit workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill behavior in that locale without indicating that users may choose another language. Under the policy, locale constraints should be optional or explicitly justified; no such opt-in or justification is provided here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed activation words include "审查", which is a generic verb meaning "review/examine" and can easily appear in ordinary conversation outside the intended skill context. The file does not provide narrowing conditions, scope constraints, or negative examples to clarify when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The comment states that actual performance checks will parse AST, but the function currently does nothing. While not directly exploitable as code execution, this is a security-relevant integrity issue because users may overestimate the analyzer's coverage and approve unsafe or inefficient code based on false assurance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.