Back to skill

Security audit

技能盘点与效能体检

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local skill-inventory tool with disclosed, user-triggered write paths and no evidence of hidden network, persistence, or destructive behavior.

Install only if you are comfortable letting the skill inspect local skill folders and related automation or hook configuration. Use the default read-only report first; only run apply/write flags after reviewing the candidates and confirming the backup and reversal path are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (34)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · README.en.md (reported line 48)May include surrounding context.

OptionMeaning
auto (default)automatic — the Agent decides per conversation language via --lang; if unset, falls back to env SKILL_INV_LANG → system locale → Chinese
zhalways respond in Chinese
enalways respond in English
bash

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · README.en.md (reported line 49)May include surrounding context.

OptionMeaning
auto (default)automatic — the Agent decides per conversation language via --lang; if unset, falls back to env SKILL_INV_LANG → system locale → Chinese
zhalways respond in Chinese
enalways respond in English
bash

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.en.md (reported line 28)May include surrounding context.

md
| Option | Meaning |
|--------|---------|
| `auto` (default) | automatic — the Agent decides per conversation language via `--lang`; if unset, falls back to env `SKILL_INV_LANG` → system locale → Chinese |
| `zh` | always respond in Chinese |
| `en` | always respond in English |

- **View**: `--show-lang` prints the current setting, all three options with descriptions,

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.en.md (reported line 29)May include surrounding context.

md
| Option | Meaning |
|--------|---------|
| `auto` (default) | automatic — the Agent decides per conversation language via `--lang`; if unset, falls back to env `SKILL_INV_LANG` → system locale → Chinese |
| `zh` | always respond in Chinese |
| `en` | always respond in English |

- **View**: `--show-lang` prints the current setting, all three options with descriptions,

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · scripts/skill_inventory.py (reported line 788)May include surrounding context.

python
| Option | Meaning |
|--------|---------|
| `auto` (default) | automatic — the Agent decides per conversation language via `--lang`; if unset, falls back to env `SKILL_INV_LANG` → system locale → Chinese |
| `zh` | always respond in Chinese |
| `en` | always respond in English |

- **View**: `--show-lang` prints the current setting, all three options with descriptions,

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · scripts/skill_inventory.py (reported line 789)May include surrounding context.

python
| Option | Meaning |
|--------|---------|
| `auto` (default) | automatic — the Agent decides per conversation language via `--lang`; if unset, falls back to env `SKILL_INV_LANG` → system locale → Chinese |
| `zh` | always respond in Chinese |
| `en` | always respond in English |

- **View**: `--show-lang` prints the current setting, all three options with descriptions,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
| 技能目录 | ✅(已知平台可自动探测) | 每个子目录 = 一个技能(含 `SKILL.md` 即可);其他平台用 `--root <目录>` |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a local inventory/health-check skill with no network access and only two narrow consent-gated write paths. This documentation states the skill publishes to SkillHub and ClawHub and provides operational guidance for external publication, which materially exceeds the declared local, non-network scope.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The script can write to disk in two places: ~/.workbuddy/settings.json and ~/.workbuddy/skill-inventory.json, and also creates backup files. Although the writes are disclosed and gated behind explicit flags, this is still a real state-changing capability with cross-session persistence, so if the host permission model did not authorize file writes, the capability is broader than declared and could disable skills or persist preferences unexpectedly.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The script can write to disk in two places: ~/.workbuddy/settings.json and ~/.workbuddy/skill-inventory.json, and also creates backup files. Although the writes are disclosed and gated behind explicit flags, this is still a real state-changing capability with cross-session persistence, so if the host permission model did not authorize file writes, the capability is broader than declared and could disable skills or persist preferences unexpectedly.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The script can write to disk in two places: ~/.workbuddy/settings.json and ~/.workbuddy/skill-inventory.json, and also creates backup files. Although the writes are disclosed and gated behind explicit flags, this is still a real state-changing capability with cross-session persistence, so if the host permission model did not authorize file writes, the capability is broader than declared and could disable skills or persist preferences unexpectedly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
Office-agent skill inventory & health check. Scans any skills directory, measures size and
  context-token footprint, detects duplicates, and classifies skills into used / protected /
  closeable / manual-review buckets. Reverse-dependency scanning locks every skill referenced by
  automations, hooks or plugins. Read-only by default: two disclosed, consent-gated write paths —
  `--overrides --apply --yes` (programmatic close on platforms like WorkBuddy; auto-backup first,
  dry-run without --yes) and `--set-lang` (saves the report language preference to
  ~/.workbuddy/skill-inventory.json). Report language: auto (default; the Agent decides per

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The language-setting section states that when no explicit parameter is provided, auto mode falls back through environment variable and system locale to Chinese. This creates a default locale constraint that can force a specific language even when the user has not opted into it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command memo includes skillhub publish and npx clawhub@0.23.3 ... publish, which are capabilities for distributing software to third-party services rather than scanning and classifying local skills. Even as documentation, these capabilities are not justified by the stated purpose of an office-agent inventory and health-check skill.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.en.md:106