Back to skill

Security audit

Thunder Core

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Thunder/Xunlei download helper; it has expected network and disk-write effects, but no evidence of hidden, deceptive, or unrelated runtime behavior.

Install only if you want Codex to help control a local Windows Thunder/Xunlei client. Before committing tasks, review the URL, save path, file size, and any custom headers, and avoid using real session cookies unless you understand they may be sent to the download source.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger phrases are broad generic words such as '下载', '迅雷', and '管理下载', which can match ordinary conversation and cause the skill to activate unexpectedly. Because this skill can create and commit download tasks on a Windows host, overbroad activation increases the chance of unintended network actions, file writes, and misuse without clear user intent.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The documentation promotes adding download tasks, committing them, cancelling tasks, and setting Referer/User-Agent/Cookie headers without warning that these actions can affect the local system, consume bandwidth/storage, and expose or replay sensitive session data. In this skill’s context, custom header support is particularly sensitive because cookies and spoofed headers can be used to access protected resources or impersonate a browser session.

Static analysis

No suspicious patterns detected.