Back to skill

Security audit

MicroService Metric Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill gives guidance for analyzing Java code to suggest business metrics and does not include hidden execution, persistence, or data export behavior.

Install this if you want Chinese-language assistance identifying metrics in Java business code. Be aware that broad trigger phrases may invoke it for some general monitoring requests, so confirm the agent is only analyzing the files you intended, especially before allowing optional project-wide AOP scanning.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase “业务指标” is broad enough to overlap with ordinary analytical requests, increasing the chance that this skill is invoked when a user did not specifically intend metric-log analysis. In an agent system, overbroad triggers can cause incorrect routing, unexpected file scanning, and analysis on irrelevant code, which is a genuine security and safety boundary issue even without malicious intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

文件的描述和后续说明全部以中文给出,且没有声明可根据用户偏好切换语言或支持多语言输出。对于非中文用户,这构成默认强制特定语言的行为,而不是基于用户选择的语言呈现。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase “添加监控” is overly generic and can match many unrelated observability, alerting, tracing, or ops requests. This makes accidental activation more likely, which can lead the agent to apply this skill outside its intended scope and potentially inspect code or propose changes inappropriately.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.