Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
- 声明描述的核心能力是评估 Skill 的质量并自动评分,但给出的代码片段只是在本地检查 Python 运行环境是否满足最低版本要求。虽然环境检查可能是某个更大系统的辅助组件,但就该代码片段本身而言,其实际行为与声明的主要用途明显不一致。代码没有读取或分析 Skill 包、SKILL.md,也没有执行任何审查、评分、诊断逻辑,因此应判定为描述与行为不匹配。
Security audit
Security checks for vulnerabilities and agentic risk
This is a read-only skill reviewer whose behavior matches its stated purpose, with some broad trigger wording but no hidden mutation, credential access, network use, persistence, or target-code execution found.
Install only if you want an agent to inspect skill packages or SKILL.md content for review. When using it manually, run its bundled scripts from this skill package, not scripts from the package being reviewed, and expect some Chinese-first output from the command-line helpers.
Detected: suspicious.dynamic_code_execution