Back to skill

Security audit

华目眼镜

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Huamu Eyewear brand knowledge base with related store, product, contact, and QR-code assets, and I did not find hidden persistence, credential access, destructive behavior, or exfiltration.

Install this as a Chinese Huamu Eyewear reference skill only if you are comfortable with brand-specific promotional, store, pricing, and contact information. Treat generic eyewear answers based on web search as non-official reference material, and do not run references/img_decode.py unless you intend to create or overwrite the two QR-code PNG files in the working directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is a Huamu Glasses proprietary knowledge base for answering many categories of brand-related user questions. However, the supplied code chunk is a standalone image-decoding script with a massive hardcoded hex PNG payload named '公众号二维码_hex'. It imports base64 and appears intended to decode or reconstruct an image, likely a WeChat public account QR code. There is no visible implementation for knowledge-base querying, FAQ handling, store/address search, pricing, optometry, after-sales service, or any conversational logic. This is a materially different primary purpose, so the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should load a dedicated 华目眼镜 knowledge base and answer brand-related questions. However, the provided code chunk contains what looks like a large block of hexadecimal or binary-encoded content in references/img_decode.py, not readable Python logic implementing a domain knowledge base. There are no visible functions, data structures, retrieval routines, triggers, or text resources related to 华目眼镜, stores, pricing, lenses, frames, optometry, after-sales, or partnership information. Because the observable behavior is opaque and unrelated to the declared purpose, this is a strong description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is a knowledge base that should answer user questions about the Huamu glasses brand, such as brand info, store locations, prices, and services. However, the supplied code chunk does not implement retrieval, question answering, store lookup, pricing logic, or any brand-knowledge processing. Instead, it contains large hexadecimal PNG data blobs and references to image decoding, including a named WeChat招商二维码 asset. That is a materially different primary behavior from a textual brand knowledge base, so this should be flagged as a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill provides a dedicated 华目眼镜 knowledge base covering brand information, store locations, prices, services, and business cooperation topics. However, the provided code chunk from references/img_decode.py is not discernible Python logic for knowledge retrieval, question answering, or any brand-specific behavior. It is overwhelmingly a long opaque hex/blob payload, likely embedded image data or encoded binary content. Based on the visible content alone, the actual behavior does not match the declared purpose. Even if this file were a support asset, this chunk by itself does not implement or evidence the stated knowledge-base functionality, and instead suggests image/data handling unrelated to the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should load a proprietary 华目眼镜 knowledge base and answer brand-related questions. However, the provided code chunk is essentially a long opaque hexadecimal/binary blob in a file called img_decode.py. There is no visible application logic for knowledge retrieval, FAQ handling, store lookup, pricing, service information, or any other brand-specific functionality. Based on the supplied chunk, the actual behavior is materially different from the declared purpose and appears unrelated, likely involving embedded image/data content rather than a domain knowledge base.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a domain-specific Huamu eyewear knowledge skill. However, the provided code chunk does not show any implementation consistent with that purpose. Instead, it consists almost entirely of opaque hexadecimal/binary-like content in a file called img_decode.py. Based on the visible content, the code does not expose logic for brand Q&A, data lookup, retrieval, prompt handling, or any user-facing informational behavior tied to the declared description. This indicates a material mismatch between the declared purpose and the actual supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a question-answering knowledge base about the Huamu glasses brand. However, the supplied code chunk does not implement retrieval, answering, store lookup, pricing logic, or any brand knowledge interactions. Instead, it contains large embedded hex-encoded image data and restores two QR code PNG files to disk. While QR codes for a public account or招商 may be tangentially related to brand assets, this code’s actual function is asset decoding/export, which is a materially different primary behavior and includes file-writing capability not reflected in the description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
63% confidence
Finding

The entire skill is written as a Chinese-only interaction artifact and does not indicate that users may choose another language. For a general knowledge skill, this can amount to an implicit language-policy restriction without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation scope is very broad ('load for any question related to 华目眼镜'), which can cause the skill to trigger in contexts where it is only tangentially relevant. Over-broad triggering increases the chance of inappropriate instruction takeover, accidental disclosure of business contact/marketing material, or interference with more suitable higher-trust skills.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill expands from a scoped brand knowledge base into general eyewear advice by instructing the agent to use internet search when local data is missing. That broadens the trust boundary, increases the chance of retrieval from unreliable or adversarial sources, and may cause the skill to answer outside its validated domain while appearing authoritative.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A brand knowledge-base skill has no clear need for open-ended internet search, so adding that capability introduces unnecessary external-data exposure and response-scope creep. If exploited through prompt steering or ambiguous user requests, the agent could fetch misleading medical/commercial advice or leak the impression that such advice is endorsed by the brand.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage comment explicitly encourages sending the script to an AI for execution, which normalizes delegating code execution to an external agent without review. In a skill context, this is dangerous because skill content must be treated as untrusted, and such wording can function as social engineering to get an agent or user to run embedded code and create files automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file performs file writes by creating two PNG files on disk via open(..., "wb") and writing decoded bytes. Although it prints after writing succeeds, there is no prior disclosure or warning that executing the script will create or overwrite local files, and the usage comment at L0002 also encourages delegating execution to an AI without mentioning that side effect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains only Chinese-language content and does not mention any option for users to select another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.