Back to skill

Security audit

Write Plan

Security checks for vulnerabilities and agentic risk

Overview

This is a low-impact planning helper with overly broad triggers and unrelated pasted learning content, but no executable code, credential access, persistence, or hidden behavior.

Before installing, consider narrowing the activation phrase and removing the unrelated Bilibili sections so the skill only loads when you explicitly want an implementation plan. The reviewed artifact does not show sensitive access or automatic system changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase 'write plan' is broad enough to collide with ordinary user requests, making the skill likely to activate outside narrowly intended contexts. Over-broad activation can cause unauthorized skill invocation, unexpected behavior selection, or prompt hijacking opportunities when normal conversation is misclassified as a skill trigger.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The invocation examples include generic phrases like '规划', 'plan', and '步骤', which are common in everyday conversation and highly likely to overlap with unrelated requests. This ambiguity increases accidental triggering risk and makes it easier for other content in a conversation to steer the agent into executing this skill unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill file contains large amounts of unrelated Bilibili 'learning' content that does not support the declared implementation-plan functionality. In an agent skill, irrelevant embedded content increases prompt-surface area, can confuse routing or downstream reasoning, and creates a channel for accidental or adversarial instruction contamination even if this specific text is not overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill defines trigger scenarios in Chinese while also including the English term "plan", but it does not state whether the skill is intended for a specific language audience or how user language preference is handled. This can create an implicit language/locale behavior without clear opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.