Back to skill

Security audit

EVR Framework

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow skill that transparently tells agents to execute, verify, and report work rather than claim completion without evidence.

Install this if you want agents to give evidence-backed status reports. Keep normal safeguards for destructive commands, permission changes, services, and network checks; the EVR process should not replace asking for confirmation when a task has real side effects.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

✅ EVR正确方式:

text
🔧 Execute
$ rm /path/to/file.txt
[无输出,命令成功]

✅ Verify

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title explicitly presents the skill as an AI tool in Chinese ("AI三步法工具"), indicating a fixed language/locale expectation. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a justified regional constraint is documented, which is not present here.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

md
| 步骤 | 含义 | 命令示例 |
|------|------|---------|
| 🔧 **Execute** | 实际执行 | `chmod 600 file` |
| ✅ **Verify** | 验证结果 | `stat -c "%a" file` → `600` |
| 📋 **Report** | 完整汇报 | "权限已修改: 644→600, 验证通过" |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
| 步骤 | 含义 | 命令示例 |
|------|------|---------|
| 🔧 **Execute** | 实际执行 | `chmod 600 file` |
| ✅ **Verify** | 验证结果 | `stat -c "%a" file` → `600` |
| 📋 **Report** | 完整汇报 | "权限已修改: 644→600, 验证通过" |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level description states the skill in Chinese and frames it as a mandatory workflow tool, but nowhere in the file does it offer the user a choice of language or explain a region-specific need for Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The integration snippet prescribes required behavior entirely in Chinese and says all tasks must follow it, but does not indicate that users or downstream agents may choose another language. This creates a language-policy issue because the enforced instructions are locale-specific without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file is explicitly titled as an English README and links to a Chinese version, but it does not present language selection as a user choice within the skill behavior or documentation flow. This can be read as a locale/language policy preference embedded in the documentation rather than an opt-in choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.