Back to skill

Security audit

批量文件处理工具箱

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a file-management skill whose file-changing capabilities fit its stated purpose, with a safety documentation gap users should notice.

Before installing, treat this as a tool that may rename, move, convert, compress, or deduplicate files. Use it only on folders you intentionally select, keep backups for important data, and ask the agent for a dry run or preview before allowing bulk changes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises bulk renaming, organization, conversion, compression, and duplicate detection but provides no warning that these actions can overwrite, move, rename, or delete files at scale. In a file-processing context, omission of confirmation, backup, or recovery guidance increases the chance of destructive user actions and data loss.

Static analysis

No suspicious patterns detected.