Back to skill

Security audit

Build

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed project-skill generator that writes local workspace files only after preview and delivery confirmation, though its activation wording is broad enough that users should install it deliberately.

Install this if you want an agent to guide projects through local Markdown plans, decisions, and review files. Expect it to create workspace directories, install generated skills when you confirm direct installation, and maintain persistent local project notes; use the ZIP option if you want to inspect or share the generated skill before placing it in a workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation criteria are extremely broad and match ordinary requests like 'write X', 'make X', or general project-planning statements, which can cause this skill to trigger when the user likely intended direct assistance instead of installing or generating a project-management skill. Because the skill has write and bash tools and its later phases create files, directories, and ZIP packages, an over-broad trigger increases the chance of unintended filesystem actions and context hijacking.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger condition is broad enough to match routine phrases like '继续' or '接下来', causing the skill to activate outside clearly scoped project-building requests. In practice this can lead to unintended tool use and file-management behavior in conversations where the user did not explicitly ask to enter a managed build workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger text is intentionally broad enough to fire on very common phrases such as '继续', '接下来', and generic project-building intents, which can cause the skill to activate when the user did not explicitly ask for project management behavior. In this skill, unintended invocation is more dangerous because activation leads to autonomous file reads, directory creation, planning state changes, and workflow steering, amplifying the effect of a false trigger.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger examples are broad enough that an agent may activate this skill for generic build or coding requests, shifting behavior from direct task execution into workspace-modifying project-skill generation. In a system with multiple installed skills, overly broad activation criteria can cause unintended invocation and unexpected file creation or planning flows the user did not explicitly request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that the generated skill is installed into the current workspace and shows a directory tree that will be created, but it does not clearly warn up front that local files and folders will be written automatically. This can lead to surprising workspace modification, especially if activation was ambiguous or the user expected only conversational guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Forcing output to the detected conversation language without asking the user can cause unsafe misunderstandings in generated build artifacts, especially for technical or operational content where exact wording matters. In a skill that generates persistent files and guidance used over a project's lifecycle, automatic language coercion may also override team conventions or reduce reviewability by collaborators.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and usage instructions are entirely in Chinese, which effectively forces a specific language for users of this checklist. Under the policy, language constraints should either provide user choice or be clearly justified as region- or locale-specific, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire guide is written as an instruction template in Chinese and directs generation of structured project retrospectives in that locale, but it does not offer an opt-in, alternative language, or justification for a Chinese-only requirement. This can violate language/locale policy when the skill is used in broader contexts where users have not explicitly chosen Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire guide is written as Chinese-only operational instruction, including the title and all workflow steps, with no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions and user-facing strings are written exclusively in Chinese and imply the skill operates in that language by default. There is no opt-in, language selection, or stated reason that the skill must be Chinese-only, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create directories and overwrite multiple project files as part of startup and ongoing execution, but it does not require a clear upfront warning and consent before those filesystem changes occur. Combined with the broad trigger behavior, this increases the chance of silent or surprising modification of user files and persistent workspace state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description and prescribed user-facing strings are written as fixed Chinese outputs, indicating the skill is intended to operate in Chinese by default. The file does not offer a language choice or explain that the skill is region-specific, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The startup protocol directs the agent to create the project directory if it does not exist and later repeatedly overwrite project files, but it does not require an upfront warning or explicit user consent before modifying the filesystem. In context, this is risky because the skill is designed for repeated autonomous progression, so a mistaken or ambiguous invocation can cause persistent changes to user files without clear authorization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README is predominantly written in Chinese and presents the skill's interaction model and examples in that language, but it does not explicitly offer users a language or locale choice. Because language preference can be a policy-sensitive UX issue, the documentation should clarify that users may interact in their preferred language if supported.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Offering ZIP packaging and direct installation without a clear warning about resulting local artifacts can cause users to approve actions without understanding that files or archives will be created on disk. The impact is lower than direct workspace installation because the behavior is described as a post-generation choice, but it still lacks explicit artifact and location disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.