Back to skill

Security audit

nuwa-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it asks agents to search broad local drives and automate web scraping without enough scoping or consent controls.

Review before installing. Only use this skill if you are comfortable with an agent searching local drives and automating web collection; preferably revise it first to require explicit source paths, approved domains, a preview of files/articles to read, redaction before publishing, and a pinned install URL with a checksum or commit hash.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:33
Finding

Overbroad Local Filesystem Access

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Installation from a Mutable Remote Branch

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

bash
# 从 GitHub 安装(推荐)
hermes skills install https://raw.githubusercontent.com/dxy0905/qiushuzhifang-skills/main/skills/nuwa-skill/SKILL.md

蒸馏工作流(三源调研法)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs inspection of broad local paths (E:\ and D:) and extraction of content from arbitrary documents, which can expose unrelated sensitive data far beyond what is necessary to generate a skill. Because the access scope is filesystem-wide and not constrained by explicit user-provided files or consent, this creates a real privacy and data-minimization risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation tells the agent to inspect local drives and documents without presenting a clear privacy notice or user-facing warning about the sensitivity of that access. In context, the skill is framed as a general research/distillation tool, so users may not reasonably expect broad filesystem inspection, making the omission security-significant.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs automated scraping using cookies, browser automation, redirect following, and recursive extraction of linked articles, which materially expands behavior beyond simple research. This can trigger unauthorized collection, excessive browsing automation, and retrieval of content from destinations the user did not explicitly approve.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The network collection section describes scraping and downloading external content without warning the user that automated browsing, cookie use, redirect following, and multi-page collection may occur. This lack of transparency can lead to unexpected data collection, policy violations, or external requests made on the user's behalf.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and include common terms such as '女娲', '造人', and '优化skill', increasing the chance of accidental activation during unrelated conversations. In a skill that can inspect local files and scrape the web, unintended invocation materially raises the risk of unplanned data access and external actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.