Back to skill

Security audit

Data Knowledge Architect — Model the Meaning Behind Your Data

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local data-modeling workflow that creates review and export artifacts, with no evidence of hidden network access, persistence, or destructive behavior.

Install only if you want an agent to read supplied API/CLI/database contracts and generate local semantic-model artifacts. Review generated files before relying on them, and keep sensitive contracts or schemas out unless they are needed for the modeling task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
dimensions, measures, and routing. Inject model JSON into `assets/review-template.html`; record

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document declares lang="zh-CN", which forces a specific language/locale for the skill UI. Under the policy, locale constraints should offer user choice or be clearly justified as region-specific, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/ingest.md (reported line 5)May include surrounding context.

md
Normalize supplied interfaces into one complete operation inventory before modeling.

| Source        | Extract                                                                                             | Grain clues                                                           |
| ------------- | --------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------- |
| REST/OpenAPI  | path+method operation; parameters/requestBody inputs; 2xx schema outputs                            | array element is often one row; object is often one resource snapshot |
| CLI           | subcommand operation; flags inputs; JSON/example output; classify read/write from observed contract | list often yields detail facts; show/get often yields snapshots       |

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to write feedback to amendments.md and regenerate artifacts, but it does not prominently warn the user that workspace files will be modified. This can lead to unexpected file creation or overwriting during normal use, reducing user control and auditability even if the behavior is part of the intended workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.