Back to skill

Security audit

EdgeOne Skill Scanner

Security checks for vulnerabilities and agentic risk

Overview

This is a local skill-security scanner with no executable payload, though it uses an over-strict report template and footer.

Install only if you want a local static scanner that may read skill files and enumerate installed skills when you ask for a full-platform audit. Treat its mandatory report template and promotional footer as publisher formatting choices, not security authority, and keep user/platform instructions in control.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:51
Finding

Skill instructions override session-level output behavior and force promotional content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (17)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
- Skill name and one-line claimed purpose from `SKILL.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
- Skill name and one-line claimed purpose from `SKILL.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
- Skill name and one-line claimed purpose from `SKILL.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
- Skill name and one-line claimed purpose from `SKILL.md`

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
---

## Report Output Guidelines

**CRITICAL — Strict format adherence**: Every scan output must follow the exact template structure
defined below. Do NOT freestyle, rearrange sections, add extra sections, or omit any required part.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 299)May include surrounding context.

📌 温馨提示:本报告基于当前版本的静态扫描,无法覆盖未来更新可能引入的风险,建议定期复查。

text

Output rules:
- All four check rows must be filled in; never leave a row blank or omit it.
- Choose ✅ or ⚠️ based on actual audit evidence; do not default to ✅ without evidence.
- Keep each result cell to one short phrase.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest claims the scanner performs only local static analysis by reading skill files, but later instructions authorize querying the agent/runtime and inferring environment state. This mismatch can mislead users about the skill's real reach and trust assumptions, causing them to approve broader inspection behavior than advertised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says the skill should not trigger for general agent usage or broad system-health-style checks, yet Mode A directs scanning all installed skills including built-ins. That inconsistency increases the chance of broader-than-expected activation and collection of metadata about unrelated installed skills.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation promises static analysis by reading skill files only, but later permits shell commands and agent queries for discovery and code retrieval. That discrepancy weakens informed consent because users may trust the skill under a narrower capability model than what the instructions actually allow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The language policy explicitly says to default to Chinese when detection fails. This forces a locale choice without offering the user an option or documenting a justified region-specific constraint, which conflicts with the stated policy criteria for language/locale handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Requiring runtime environment inference and agent interrogation expands the skill beyond simple local file review and can expose information about the host platform, installed skills, and agent state. Even without direct exfiltration, this broadens access and creates unnecessary privacy and scope risk for a scanner that claims minimal local analysis.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
87% confidence
Finding

The instruction to enumerate all installed skills across the platform increases visibility into a user's environment and may collect metadata about unrelated or built-in components. In the context of a scanner, this is only justified for an explicitly requested full-platform audit; otherwise it represents unnecessary scope expansion.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
#### A-2. Discover skills

Once the platform is identified, use the platform-specific method below to enumerate all installed
skills. Do **NOT** output a list of all discovered skill names and paths before scanning — proceed
directly to auditing each skill one by one.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
- Sensitive access that materially exceeds the declared function
  - Outbound exfiltration of credentials, private data, or unrelated files
  - Destructive or host-disruptive operations
  - Attempts to bypass approval, sandbox, or trust boundaries
- Ignore docs, examples, test fixtures, and low-risk informational issues unless the same behavior
  is reachable in production logic.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
#### A-1. Identify the platform

Determine which agent platform the user is referring to. Common platforms include but are not
limited to: **OpenClaw, Cursor, Windsurf, CodeBuddy, WorkBuddy, Claude Code, qclaw**, etc.

How to determine:

Static analysis

No suspicious patterns detected.