Back to skill

Security audit

Swe Bench A6e0fc

Security checks for vulnerabilities and agentic risk

Overview

The skill does not appear to run code or access data, but its broad triggers and mixed unrelated content could make it activate in the wrong conversations.

Review this skill before installing if you use skills that auto-activate by trigger words. It has no obvious code-execution or data-access behavior, but it should be narrowed and deduplicated so ordinary mentions of Claude, Code, SWE-bench, or ASPICE do not unexpectedly steer the agent with mixed guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest advertises a SWE-bench / AI coding comparison skill, but much of the embedded content is unrelated ASPICE template and review-process material duplicated multiple times. This mismatch can cause the wrong skill to activate and deliver irrelevant or misleading guidance, which is a security and reliability risk in agent environments because users and downstream systems may trust the declared purpose rather than the actual content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill description is presented in Chinese and the document consistently frames the skill content and trigger language in Chinese, without offering any language choice or stating that the skill is region- or locale-specific. This can violate language/locale policy when users have not opted into Chinese-only behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger field contains broad/common terms like SWE-bench, Claude, and Code, which are likely to appear in ordinary conversation and unrelated tasks. Overbroad triggers can cause accidental activation of this skill in contexts where it does not belong, leading to prompt hijacking of the agent's behavior and propagation of mismatched instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation examples use ambiguous conditions such as a user saying 'SWE-bench' or needing related help, without defining boundaries for when the skill should or should not run. In an agent system, this can make the skill activate on incidental mentions and steer responses away from the user's actual intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The repeated trigger scenario again uses generic 'user needs ... related help' wording, which is too broad and can match many unrelated workflow or compliance discussions. Repetition of these broad conditions increases the chance of unintended activation and makes the skill's scope harder to audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This repeated trigger block continues to define activation in overly generic terms, creating unnecessary activation surface. In practice, such broad matching can let stale or irrelevant embedded content influence the agent during unrelated requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The final repeated trigger scenario preserves the same generic wording, compounding accidental invocation risk across multiple duplicated sections. The duplicated broad triggers make the file especially error-prone because any trigger parser may treat all of them as active scope definitions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.