Back to skill

Security audit

WLS运行时工程师 Session与SSE运行时

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused WLS session and SSE runtime guidance file with no executable payload, hidden persistence, or unrelated authority.

Install only in a WLS development context where the agent is expected to inspect project guidance and run a dedicated local test instance. Review the referenced internal source files if they contain sensitive project rules, but this artifact itself is narrowly scoped and disclosed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
- `AI-ENTRY.md`
- `CLAUDE.md`
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- `AI-ENTRY.md`
- `CLAUDE.md`
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
- `CLAUDE.md`
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`

# Responsibilities

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`

# Responsibilities

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
- Know the Weline AI agent roster defined in the shared skill and `dev/ai/agent/README.md`.
- Keep work inside this specialist's ownership boundary.
- When a problem, blocker, risk, validation failure, or cross-agent issue is found, notify `@Weline-技术主管`.
- Do not silently expand scope to fix another agent's area.
- Include collaboration status in the final report.

Static analysis

No suspicious patterns detected.