Back to skill

Security audit

Performance Profiling

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent performance-profiling reference, but it includes disruptive database and load-testing commands without enough safety scoping.

Install only if you are comfortable reviewing commands before execution. Use these examples only on systems and services you own or are authorized to test, avoid production unless approved, preserve diagnostic logs before clearing them, and prefer pinned, locally installed profiling tools over global or latest-version installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Python and Node.js Profiling Dependencies

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/load-test.md:40
Finding

Mutable Go Tool Installation Using the Latest Version

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/system.md:57
Finding

Execution of Scripts from a Mutable Git Repository

Content
View full analysis
flame.svg ``` ### Technical Analysis The `git clone` command retrieves the repository's mutable default branch without pinning a reviewed commit or verifying its signature. The following pipeline executes two Perl scripts directly from the cloned repository. Because the repository contents may change after the Skill review, compromise of the repository, maintainer credentials, hosting account, or delivery path could replace either script with attacker-controlled behavior. Piping profiling data through the scripts does not sandbox them; each Perl program runs as ordinary local code with the invoking user's permissions. There is no evidence that the referenced repository currently contains malicious code. The security concern is the trust placed in mutable remote content and its subsequent execution without validation. ### Attack Path 1. An attacker compromises the upstream repository or an authorized maintainer account. 2. The attacker modifies `stackcollapse-perf.pl`, `flamegraph.pl`, or code loaded by those scripts. 3. A user follows the documentation and clones the mutable default branch. 4. The user runs the documented pipeline. 5. The malicious Perl code executes locally while processing the profiling data. 6. The payload gains access to resources available to the invoking user. ### Impact Assessment Successful exploitation could result in arbitrary code execution with the profiling user's privileges. The payload could read project files, profiling data, process-related information, environment variables, and other files accessible to that account, and could initiate outbound network connections. ...[truncated 367 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- **Node.js 分析**: [references/nodejs.md](references/nodejs.md) - V8 分析, clinic.js

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and primary content are written in Chinese, and the file does not indicate that the skill is region-specific or provide any language opt-in. This creates a natural-language policy concern because it implicitly constrains users to a specific language without documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation includes PostgreSQL query-cancellation and termination commands without any warning about operational risk or guidance on safe use. In a performance-profiling skill, users may copy these commands into production, causing disruption to legitimate workloads, aborted transactions, or application instability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Redis section includes SLOWLOG RESET without noting that it permanently clears diagnostic history. In a troubleshooting guide, this can lead users to erase evidence needed for root-cause analysis or incident response, especially if run prematurely on a live system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document provides ready-to-run load-testing commands that can generate significant HTTP traffic, including concurrent requests and scripted POST bodies, but it does not warn users to obtain authorization or avoid running them against third-party production systems. In a skill intended as a performance-profiling reference, this omission increases the chance of misuse for accidental denial-of-service or unauthorized stress testing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file's headings, comments, and instructional text are all in Chinese, with no indication that the skill is region-specific or that users may opt into another language. This can violate language/locale policy when a skill implicitly forces a language without user choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document title and all instructional content are written exclusively in Chinese, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This is a natural-language locale constraint and may violate organizational language-choice policy when presented as a general reference skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file title and all instructional content are presented in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. This is a natural-language locale constraint that can violate organizational language-choice policy when not documented or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructions and labels in Chinese only, which can impose a specific language on users without offering a choice. The policy explicitly calls for flagging language or locale constraints when they are forced without user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.