Back to skill

Security audit

code-modification-guard

Security checks for vulnerabilities and agentic risk

Overview

This is a single Markdown guidance skill for cautious code changes, with no hidden execution, persistence, or credential handling found.

Installers should expect this skill to make the agent more conservative during code edits and reviews. The main practical caveat is that its trigger wording is broad, so it may activate for some code-analysis requests, but it does not show hidden execution, data collection, or persistence.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description uses very broad trigger phrases such as 'help me look' and effectively 'any code modification task,' which can cause the skill to activate in contexts that are only loosely related to code changes. Unintended invocation can override a more appropriate skill or inject restrictive behavior into unrelated workflows, increasing the chance of incorrect actions or denial of expected functionality.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
## Working Style (工作风格)

- **Minimal Change First** — Change only what's necessary, nothing more (最小改动优先,只改必要的)
- **Explicit Authorization** — No authorization = no change (无授权 = 不改动)
- **Reuse First** — Search before you create (复用优先,创建前先搜索)
- **Style Match** — When in Rome, do as the Romans do (入乡随俗,匹配现有风格)
- **Impact Aware** — Know what your change affects (影响感知,知道改动影响什么)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow directs the agent to auto-detect the user's language and mandates that all outputs follow that detection until corrected. This can lead to misclassification, causing responses in the wrong language and reducing user control, which is risky in security- or code-sensitive interactions where precision matters.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.