Back to skill

Security audit

code-dev-pipeline 代码开发流水线

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent code-development workflow, but it directs agents to make broad persistent repository and filesystem changes without a clear user approval boundary.

Install only if you want a Chinese-language, highly structured development pipeline and are comfortable supervising its local side effects. Before use, require explicit confirmation before Git commits, avoid `git add .`, review staged files, and revise logging templates so generated code does not store raw personal data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/coder.md:11
Finding

Overbroad Git Staging Can Commit Unrelated or Sensitive Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/coder.md:107
Finding

Logging Templates Encourage Storage of Raw Personal and Attacker-Controlled Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares it 'must' be used for very broad triggers like writing code, implementing features, frontend work, or any request with code-quality expectations. This can cause the agent to route many ordinary coding tasks into a rigid multi-step workflow without clear user consent, overriding narrower system behavior and creating an unsafe prompt-scope expansion path. The danger is amplified because the skill is positioned as mandatory and auto-executing, so benign coding requests may be captured unintentionally and processed under adversarial skill instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and operational instructions are written as mandatory Chinese-language guidance, but there is no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and change notes are entirely in Chinese, with no indication that users can choose another language or that the locale restriction is intentional. This creates a natural-language policy concern because the skill appears to impose a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and core instruction are written entirely in Chinese and define the assistant role in Chinese without offering any language choice or opt-in. This creates a natural-language locale constraint that could conflict with organizational language policy for multilingual users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown skill specifies its role and operating instructions exclusively in Chinese, which effectively forces a specific language on users. The policy allows fixed locale/language only when users are given a choice or the constraint is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown skill file uses Chinese as the sole required operating language and does not indicate that users may opt into another language. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly requires Git commits for all code changes, which causes persistent repository modification beyond the narrow task of code implementation. In an agent setting, this can create unintended state changes, leak work into commit history, and interfere with user workflows or branch hygiene without explicit consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The logging guidance instructs recording user identifiers and email addresses in plaintext logs. This creates unnecessary exposure of personal data in log pipelines, backups, support tooling, and incident artifacts, increasing privacy and compliance risk if logs are accessed or retained broadly.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example implementation repeats the unsafe pattern by logging user email addresses in both normal request logs and error paths. Because examples are likely to be copied directly into production code, this materially increases the chance of widespread PII leakage across generated applications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is written as mandatory operating instructions in Chinese and defines the coordinator role without indicating that language should follow the user's preference. This creates a language/locale policy issue because the skill appears to force a specific language rather than offering opt-in or user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill file is written as a mandatory Chinese-language reviewer instruction and does not offer any user opt-in or alternative locale. Under the policy, forcing a specific language without user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown skill is written entirely in Chinese and explicitly requires a fixed output format using Chinese status labels like 【通过】 and 【发现bug】. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is justified or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The validator instructions hard-code Chinese-only output and do not offer any user language choice or document a legitimate locale restriction. In a general-purpose code development pipeline, this can cause users or downstream reviewers to misunderstand acceptance results, miss blocking issues, or fail to validate whether security and quality requirements were actually met.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document is written entirely in Chinese and embeds Chinese-only prompt instructions for all roles, with no indication that users may select another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow explicitly persists generated artifacts to the local filesystem and updates a current symlink automatically, but it provides no consent gate, path safety checks, or warning to the user that agent output will modify disk state. In an agent skill used for code generation, this increases risk of unintended file writes, overwrite of prior artifacts, or misuse of attacker-influenced project names/paths if later wired to untrusted input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill mandates repository-changing Git operations without clearly warning the user that it will create commits and modify project history. This reduces informed consent and can surprise users with persistent side effects, especially in shared or regulated repositories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.