T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:33- Finding
Overbroad Local Filesystem Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not clearly malicious, but it asks agents to search broad local drives and automate web scraping without enough scoping or consent controls.
Review before installing. Only use this skill if you are comfortable with an agent searching local drives and automating web collection; preferably revise it first to require explicit source paths, approved domains, a preview of files/articles to read, redaction before publishing, and a pinned install URL with a checksum or commit hash.
SKILL.md:33Overbroad Local Filesystem Access
SKILL.md:24Unpinned Installation from a Mutable Remote Branch
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
# 从 GitHub 安装(推荐)
hermes skills install https://raw.githubusercontent.com/dxy0905/qiushuzhifang-skills/main/skills/nuwa-skill/SKILL.md
The skill explicitly instructs inspection of broad local paths (E:\ and D:) and extraction of content from arbitrary documents, which can expose unrelated sensitive data far beyond what is necessary to generate a skill. Because the access scope is filesystem-wide and not constrained by explicit user-provided files or consent, this creates a real privacy and data-minimization risk.
The documentation tells the agent to inspect local drives and documents without presenting a clear privacy notice or user-facing warning about the sensitivity of that access. In context, the skill is framed as a general research/distillation tool, so users may not reasonably expect broad filesystem inspection, making the omission security-significant.
The skill directs automated scraping using cookies, browser automation, redirect following, and recursive extraction of linked articles, which materially expands behavior beyond simple research. This can trigger unauthorized collection, excessive browsing automation, and retrieval of content from destinations the user did not explicitly approve.
The network collection section describes scraping and downloading external content without warning the user that automated browsing, cookie use, redirect following, and multi-page collection may occur. This lack of transparency can lead to unexpected data collection, policy violations, or external requests made on the user's behalf.
The trigger phrases are broad and include common terms such as '女娲', '造人', and '优化skill', increasing the chance of accidental activation during unrelated conversations. In a skill that can inspect local files and scrape the web, unintended invocation materially raises the risk of unplanned data access and external actions.
No suspicious patterns detected.