Back to skill

Security audit

内容生成技能包

Security checks for vulnerabilities and agentic risk

Overview

This writing skill is not clearly malicious, but it asks for external tools, an API key, and an npm install without explaining why users should grant them.

Review before installing. The skill appears to be instruction-only writing guidance, but it requests external tools, a Brave API key, and an npm dependency without explaining their need or how user drafts and prompts are handled. Avoid using it with confidential content unless the publisher removes or clearly documents those external capabilities.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned and Unnecessary Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9-15
Vulnerability Type: Unpinned npm dependency and excessive unused prerequisites
Risk Level: Medium

Vulnerable Code:

yaml
requires:
  bins: ["curl", "jq", "git"]
  env: ["BRAVE_API_KEY"]
install:
  - id: npm
    kind: node
    package: axios
    bins: ["axios"]

Technical Analysis

The skill is instruction-only and contains no implementation that uses Axios. Nevertheless, its installation metadata directs the host to install axios without an exact version or integrity constraint. This causes the resolved package and transitive dependency graph to vary over time, unnecessarily exposing installation environments to npm supply-chain and package-lifecycle risks.

The metadata also declares an axios executable even though Axios is ordinarily consumed as a JavaScript library. In addition, the requested curl, jq, git, and BRAVE_API_KEY capabilities are not used by any documented command or implementation in the reviewed package. No instruction was found that reads or transmits the API key, but requesting unused tools and credentials violates least-functionality principles and broadens the environment available to future or compromised dependencies.

Exploitation depends on malicious or compromised content entering the package or its dependency graph. The reviewed files do not themselves contain malicious code, remote payload execution instructions, or credential-exfiltration logic.

Attack Path

  1. A user installs or activates the skill.
  2. The host processes the npm installation metadata in SKILL.md.
  3. Because no exact Axios version or integrity hash is specified, the package manager resolves a currently available release and its transitive dependencies.
  4. If the resolved package or a transitive dependency is compromised or unexpectedly changed, package installation behavior may run in the host environment.
  5. Su ...[truncated 807 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the Axios installation block because no reviewed project code uses Axios.
  2. Remove the curl, jq, git, and BRAVE_API_KEY requirements unless concrete skill functionality requires them.
  3. If Axios is later required, pin an exact reviewed version rather than using an unconstrained package reference.
  4. Maintain a lockfile with integrity hashes and review the complete transitive dependency graph.
  5. Disable or restrict dependency lifecycle scripts where the deployment environment permits.
  6. Do not declare Axios as a CLI binary unless a specific, verified executable is actually required.
  7. Provide sensitive credentials only at the point of use and only to the process that requires them.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill requests external binaries (curl, jq, git) and a BRAVE_API_KEY despite being presented as a generic content-generation skill, but the file provides no operational logic or user-facing disclosure explaining why network access or external APIs are needed. This creates unnecessary capability and data-exfiltration risk because a caller may provide sensitive prompts or documents to a skill that can route data to third-party services without clear consent or constrained purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The metadata signals use of an external API key and the body references research capabilities, but the skill does not warn users that prompts, drafts, or attached content may be sent to outside services. This is dangerous because content-generation tasks often involve proprietary, personal, or pre-publication material, and users are not given informed consent or handling boundaries for that data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation guidance is extremely broad and maps to common writing requests, making it likely the skill will auto-trigger for generic prompts that do not clearly require this specific capability. In a system with external tools and API access, over-broad matching increases the chance that ordinary user content is unnecessarily processed by a more privileged skill than expected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.