Back to skill

Security audit

skill-inventory

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it creates a persistent skills inventory from untrusted skill text without escaping it, which could influence future agent sessions.

Review this before installing if your skills directory may contain third-party or untrusted skills. The tool should escape or strictly validate skill metadata, clearly warn before overwriting skills.md, and present generated inventory content as data rather than instructions for the agent to follow.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Error
Location
inventory.py:78
Finding

Stored Prompt Injection Through Unescaped Skill Metadata

Content
View full analysis
list: """从 SKILL.md 中提取触发词""" skill_file = skill_dir / "SKILL.md" if not skill_file.exists(): return [] triggers = [] content = skill_file.read_text(encoding='utf-8') # 查找触发词列表(简化版:匹配常见的触发词模式) lines = content.split('\n') for i, line in enumerate(lines): # 匹配触发词表格或列表 if '触发词' in line or 'trigger' in line.lower(): # 读取接下来的几行 for j in range(i+1, min(i+10, len(lines))): next_line = lines[j].strip() if next_line and not next_line.startswith('#'): # 提取引号中的内容 matches = re.findall(r'["「]([^"」]+)["」]', next_line) triggers.extend(matches) if next_line.startswith('#') or next_line.startswith('---'): break return triggers[:5] # 最多5个 ``` Untrusted descriptions are extracted without validation or Markdown escaping: ```python content = skill_file.read_text(encoding='utf-8') lines = content.split('\n') # 查找描述(第一段非注释内容) for line in lines: line = line.strip() if line and not line.startswith('---') and not line.startswith('#'): # 移除可能的 frontmatter if ':' in line and not line.startswith('name:'): info["description"] = line[:100] break elif line.startswith('description:'): # 多行描述 desc_lines = [] for j in lines[lines.index(line)+1:]: if j.strip().startswith('---'): break desc_lines.append(j.strip()) ...[truncated 3835 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to read from the skills directory and generate or update a workspace file, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, missing scope declarations can cause overbroad file access or writes to occur without clear user-visible constraints, which increases the risk of unintended file modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill tells the agent to run a command that writes or overwrites <workspace>/skills.md, but the description does not clearly warn about that side effect before execution. Lack of explicit disclosure around overwrite behavior can lead to silent data loss, unexpected state changes, or unsafe automation when users think they are only listing installed skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file presents the primary description and operating instructions in Chinese while also embedding English trigger phrases, but it does not state whether users may interact in their preferred language. This can create an implicit language expectation without explicit opt-in or documented locale scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The markdown defines activation examples, but the phrase "更新技能目录" could overlap with general requests to update a skill catalog without clearly limiting invocation to this specific local inventory generator. The file does not provide negative examples or exclusion conditions to clarify when this skill should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.