Back to skill

Security audit

Skill Scorer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent markdown-only skill-quality reviewer; its file-reading and optional URL fetching are expected for reviewing user-provided skill artifacts.

Install this only if you want a bilingual skill-audit helper. Be aware that it may activate on broad skill-review phrasing and will read the skill files or folders you point it at, including any references inside that target skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description contains very broad trigger phrases such as reviewing, scoring, auditing, or improving any skill, including casual requests like 'is this skill any good?'. In agent environments that rely on description matching for activation, this can cause the skill to fire on ordinary feedback requests and unexpectedly take over conversations, creating prompt-routing confusion and increasing the chance of context misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'When to Activate' section repeats ambiguous activation conditions like generic review or optimization requests, without strong scope checks that the target is actually a skill artifact. This broadens the chance of accidental invocation, which can lead to misrouting, unnecessary file access or fetching behavior, and incorrect handling of unrelated user content as if it were a skill audit task.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
| Single `SKILL.md` file | Evaluate that file |

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
- "需要对某个维度深入分析吗?" (deep-dive mode)
- "需要生成优化后的 SKILL.md 吗?" (rewrite mode)

## Output Rules

1. **Bilingual report — Chinese first, English after, no interleaving.** Always output the complete report in Chinese, then a `---` separator, then the complete report in English. Never mix languages within a section. Both versions must contain identical scores, issues, and suggestions — only the language differs.
2. **Score must be justified.** Every deducted point must trace to a specific issue.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/rubric.md (reported line 137)May include surrounding context.

md
- "需要对某个维度深入分析吗?" (deep-dive mode)
- "需要生成优化后的 SKILL.md 吗?" (rewrite mode)

## Output Rules

1. **Bilingual report — Chinese first, English after, no interleaving.** Always output the complete report in Chinese, then a `---` separator, then the complete report in English. Never mix languages within a section. Both versions must contain identical scores, issues, and suggestions — only the language differs.
2. **Score must be justified.** Every deducted point must trace to a specific issue.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/report-template.md (reported line 3)May include surrounding context.

md
# Report Template — skill-scorer

> **Bilingual output rule:** Always generate the FULL report in Chinese first, then a clear separator, then the FULL report in English. No interleaving. Both versions must have identical scores, issues, and suggestions.

---

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/rubric.md (reported line 267)May include surrounding context.

md
| 70-89 | Adequate safety. Minor risks (e.g., large knowledge section without disclaimer). |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that reports are always output in both Chinese and English, with Chinese first. This enforces a language/locale preference rather than offering the user a choice, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 39)May include surrounding context.

text
# 在 Claude Code 中
> 帮我评分这个 skill: .claude/skills/my-skill/SKILL.md

# 在 Claude.ai / Cowork 中
> [上传 SKILL.md 文件] 帮我质检这个 skill

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 132)May include surrounding context.

text
# 在 Claude Code 中
> 帮我评分这个 skill: .claude/skills/my-skill/SKILL.md

# 在 Claude.ai / Cowork 中
> [上传 SKILL.md 文件] 帮我质检这个 skill

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The English overview says reports are always output in both Chinese and English, with Chinese first and English after. This is a natural-language policy issue because it imposes a fixed language ordering without user opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Mandating Chinese-first bilingual output for all users imposes a fixed language policy regardless of user preference or environment expectations. This is primarily a usability and policy-compliance issue rather than a direct exploit, but it can degrade reliability, increase token usage, and cause mismatches with downstream systems expecting a single language or user-selected locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template hard-codes a Chinese-first bilingual response regardless of user preference or execution context. This is a prompt-policy constraint that can override caller intent, increase token usage, and cause unnecessary disclosure or transformation of user-provided content into an additional language, which is undesirable in security-sensitive or minimal-output workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.