Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md dimensions, measures, and routing. Inject model JSON into `assets/review-template.html`; record
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent local data-modeling workflow that creates review and export artifacts, with no evidence of hidden network access, persistence, or destructive behavior.
Install only if you want an agent to read supplied API/CLI/database contracts and generate local semantic-model artifacts. Review generated files before relying on them, and keep sensitive contracts or schemas out unless they are needed for the modeling task.
Referenced artifact was not completely inspected
dimensions, measures, and routing. Inject model JSON into `assets/review-template.html`; record
The document declares lang="zh-CN", which forces a specific language/locale for the skill UI. Under the policy, locale constraints should offer user choice or be clearly justified as region-specific, neither of which appears in this file.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
Normalize supplied interfaces into one complete operation inventory before modeling.
| Source | Extract | Grain clues |
| ------------- | --------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------- |
| REST/OpenAPI | path+method operation; parameters/requestBody inputs; 2xx schema outputs | array element is often one row; object is often one resource snapshot |
| CLI | subcommand operation; flags inputs; JSON/example output; classify read/write from observed contract | list often yields detail facts; show/get often yields snapshots |
The skill explicitly instructs the agent to write feedback to amendments.md and regenerate artifacts, but it does not prominently warn the user that workspace files will be modified. This can lead to unexpected file creation or overwriting during normal use, reducing user control and auditability even if the behavior is part of the intended workflow.
No suspicious patterns detected.