Back to skill

Security audit

orangeink

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese WeChat Markdown renderer with local file outputs and no hidden credential, persistence, shell, or default network behavior.

Install this if you want a Chinese WeChat Markdown rendering workflow. Use it on Markdown you trust, avoid --no-check unless you intentionally want to bypass self-check output, and do not enable OIMD_REMOTE_TEMPLATE=1 or pass arbitrary HTML to parity-check unless you accept that jsdom will execute that template script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
- **结构合规**:本 skill 即 Claude Agent Skills 通用规范布局(`SKILL.md` + `scripts/` + `references/` + `tests/`),frontmatter 仅用通用字段(name / description / license / metadata)—

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/render.mjs (reported line 848)May include surrounding context.

js
'--meta': v => { args.meta = v; },
  };
  const BOOL = { // 布尔开关:不消费后续参数
    '--quiet': () => { args.quiet = true; }, '--no-check': () => { args.noCheck = true; },
  };
  for (let i = 2; i < argv.length; i++) {
    const a = argv[i];

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill is for the Chinese WeChat public-account scenario and that output will be in Simplified Chinese. This is a language/locale restriction expressed in natural language, and the file does not present it as a user choice or opt-in at that point.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The metadata explicitly sets locale: zh-CN and says the product definition is Chinese output. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly offered as a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The visible metadata and document content are entirely in Chinese, including the title and descriptive subtitle, with no indication that users may select another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.