Back to skill

Security audit

Coding Lite - 轻量级编码助手

Security checks for vulnerabilities and agentic risk

Overview

This is a small Chinese-language coding helper skill with disclosed code-generation and execution guidance, and I found no hidden payloads, persistence, credential use, or exfiltration behavior.

Install this if you want a concise Chinese-language coding helper. Review generated scripts before running them, use a sandbox or virtual environment for unfamiliar code, back up data before file or database changes, and be careful with package installs, scraping, macros, and SQL UPDATE or DELETE statements.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises Python script generation and execution but provides no warning about code execution, untrusted input, file access, dependency installation, or data exfiltration risks. In a coding assistant context, this omission is dangerous because users may treat generated or executed code as safe by default, leading to unsafe execution of harmful scripts or misuse of local data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README uses very broad natural-language trigger examples such as writing Python scripts, Excel formulas, mini-program pages, and SQL queries. In agent environments, such generic phrases can cause the skill to activate for many ordinary user requests, increasing the chance of unintended invocation and exposing users to risky capabilities like code generation or execution without clear consent boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L003 的自然语言描述完全以中文呈现,且文件中未说明是否支持按用户偏好切换语言,也未提供语言选择机制。根据规则,若技能在语言或地区上存在默认强制而无用户选择,属于自然语言策略违规风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L010 将触发场景定义为“当用户需要快速生成代码、自动化脚本、数据处理或查询时使用此技能”,覆盖面非常广,但没有列出明确触发短语、边界或排除条件。这样的描述容易让技能在大量普通编程相关对话中被误触发,属于模糊触发范围。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions and examples in the file are Chinese-only, which can amount to an implicit language constraint without user opt-in. The document does not state that the skill is region-specific or offer alternative language support, so it may violate language/locale choice expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.