Back to skill

Security audit

zhongkui-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a local skill-auditing helper whose file-reading behavior is disclosed and aligned with its security-review purpose.

Install this only if you want a local skill-review assistant. Give it explicit skill-directory paths, avoid pointing it at broad private folders, and treat its verdicts as heuristic because the permission boundaries and some advanced review claims are not tightly specified.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill text describes capabilities that imply file reading, network access, and shell-oriented analysis steps, but it does not declare corresponding permissions. This creates a trust and review gap: operators may approve or run the skill without understanding the actual access it expects, increasing the chance of over-privileged execution or unsafe deployment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The activation phrases include broad everyday expressions such as '审一下' and '查一下这个skill', which can cause accidental invocation outside a clearly intended security-review context. Over-broad triggering is dangerous for a skill with analysis capabilities because it may activate unexpectedly, inspect unintended content, or interfere with normal conversations and workflows.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/fix-strategies.md:83

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
REFERENCE.md:49

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/agent-skill-security-review.md:142

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/behavioral-emulation.md:36

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/risk-taxonomy.md:7