Back to skill

Security audit

C++ Code Review Master

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed C++ code review skill with optional, user-gated repair behavior and no packaged executable payload.

Install only if you want a C++ review workflow that may read repository code, run local read-only checks, use configured AI providers, spawn review subagents, and optionally modify files when you request fixes. Review dependent skills such as code-review-fix separately before enabling repair or autoFix.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file presents the entire skill handbook in Chinese from the title onward, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown description presents the skill in Chinese and does not indicate that other languages are supported or that the user can choose a preferred language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and invocation text are presented entirely in Chinese, and the file does not indicate that language choice is optional or region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes a very broad phrase equivalent to generic code review requests, which can cause unintended activation outside the author's intended scope. In an agent ecosystem, overly broad triggers can hijack unrelated user requests, leading to unexpected tool execution, context capture, or workflow changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

L190 明确写明“默认每步需用户确认,不会自动修改代码”,但前文 L144-L153 描述了“用户确认后”可使用 code-review-fix 自动修复,并将 /cpp-review --fix 作为标准触发方式公开。该文档没有澄清确认机制如何强制执行,导致关于是否会发生代码修改的行为表述存在明显张力,易让使用者误解技能默认执行边界。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and definitions only in Chinese, with no user opt-in, alternative language, or justification that the content is intended for a Chinese-only audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is titled and written as a C++ code review workflow in Chinese, with no indication that language is selectable or based on user preference. The policy requires flagging language or locale constraints when a specific language is forced without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Step 7 is presented as verification, but its first documented action is to perform automatic fixes. This is a misleading capability boundary: users may consent to validation while the workflow actually edits code, increasing the risk of unauthorized or unsafe modifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Documenting automatic code repair without an explicit warning about modification risk can mislead users into running a workflow that changes source code unexpectedly. In a review context, silent or insufficiently disclosed mutation is dangerous because it can introduce regressions, alter audited evidence, or overwrite in-progress work.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow for a code review skill expands into autonomous code modification by invoking code-review-fix, which exceeds the declared scope of review/reporting. This can cause unexpected source changes, reduce user control, and create a path for unsafe or incorrect edits under the guise of analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is written as a checklist entirely in Chinese, starting with the title 'C++ 专项检查清单', with no indication that other languages are supported. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.