Back to skill

Security audit

CSDN

Security checks for vulnerabilities and agentic risk

Overview

The skill is a simple Markdown-only guide with no code or persistence, but its CSDN description does not match the collaboration-software guidance it actually contains.

Review this skill before installing because it may be invoked for CSDN help but actually steer the agent toward generic collaboration-software advice. It does not appear to run code or access data, but the publisher should align the name, description, examples, and body to one clear purpose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s declared purpose is CSDN-related career development, blogs, and open-source guidance, but the body describes generic collaboration and office-software selection criteria. This mismatch can mislead downstream agents or users into invoking the skill for the wrong domain, causing unsafe reliance on incorrect capabilities and increasing the risk of prompt-routing or policy bypass through deceptive metadata.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and examples frame the skill as 'CSDN技术栈', but the listed functions and precautions map to document collaboration, permissions, version history, and sharing links instead. This contradictory framing makes the skill deceptive in practice, which can cause incorrect tool selection, user confusion, and trust erosion; in agent environments, misrepresentation of scope is a real integrity risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content of the skill is entirely in Chinese, including the description and example requests, with no indication that users may choose another language. This can violate language/locale policy where skills should not impose a language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.