Back to skill

Security audit

Vic Publish

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a courseware-building purpose, but it includes watermark-removal guidance and optional local tool, credential, and external asset workflows that deserve review before use.

Install only if you are comfortable with a Chinese-focused courseware workflow that creates local project files and may use web research. Do not follow the watermark-removal instruction; use licensed, watermark-free assets or regenerate compliant images. Choose the 3D path only if you approve local tool/config checks, Blender/ffmpeg/node execution, third-party model sources, and careful handling of any BlenderKit API key.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个“课件制作技能”,核心能力应是生成可视化、交互式 HTML 课件内容;但代码并不生成课件、SVG 演示、知识卡或教师说明,而是对已存在的 HTML 课件进行审计和评分。其主要功能是质量审核与报告输出,这是与声明的主要用途明显不同的能力。代码没有显示危险或额外越权行为,但主功能与描述不符,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill is for producing visual, interactive teaching courseware in single-file HTML form for classroom topics. However, the supplied code does not generate courseware, SVG teaching content, knowledge cards, teacher explanations, or any user-facing educational HTML. Its actual purpose is a developer-oriented packaging tool: it reads specific local library files (three.module.min.js, orbit-controls.js, bufferutils.js, gltfloader.js), rewrites module syntax using regex, emits a bundled _three_bundle.js, and invokes Node to check syntax. This is materially different from the declared instructional-content creation purpose, so the description does not accurately represent the code's behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill gives explicit instructions for removing AI-image watermarks using post-processing techniques. Watermark removal is not necessary for safe courseware creation and can facilitate copyright evasion, provenance stripping, and policy circumvention; the presence of such guidance is a strong red flag under the provided review criteria.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill contains step-by-step paraphrased guidance to remove AI-image watermarks, which directly enables misuse of generated or third-party imagery and undermines provenance controls. In context, this is unrelated to the core educational function and therefore more suspicious, not less.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill explicitly instructs file creation/modification and shell execution (for audit and bundling) but does not declare a restrictive tool scope. That gap can cause the runtime to grant broader capabilities than users expect, increasing the risk of unintended filesystem changes or command execution through this skill path.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

These lines direct the agent to inspect local executable paths and user configuration locations such as ~/.workbuddy/mcp.json and ~/.workbuddy/skills/blender-studio/. While optional 3D courseware support is within the broader educational purpose, probing local environment and installed tools is a separate system-inspection capability not clearly justified by the manifest's stated role as a courseware creation skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown explicitly requires '中文界面' at L150 as a hard rule. This is a language policy constraint stated in natural language, and the file does not indicate user opt-in or an alternative locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML root sets lang="zh-CN", and the surrounding UI text is entirely Chinese, which establishes a fixed language/locale for the skill output. The file does not offer any opt-in or alternative locale selection, and no region-specific justification is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file title and the entire procedural guidance are presented exclusively in Chinese, and the skill text does not indicate that users may choose another language or locale. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document includes instructions for authenticated BlenderKit access using an API key and direct module calls, which introduces secret-handling and third-party asset retrieval into a skill whose main purpose is generating offline courseware. This expands the trust boundary, creates risk of credential exposure or misuse, and may encourage agents to handle secrets or download unvetted external content without clear necessity or safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L19 要求“标注术语与人教版教材逐字一致”,属于将内容绑定到特定语言/教材体系的自然语言约束。文档未说明这是仅适用于中国课程场景,亦未给出其他语言或地区版本的选择,因此存在语言/locale 策略约束未充分声明的问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L56 规定“术语与对应学段教材一致(初中人教版/高中新课标/高职规划教材)”,这是面向所有内容的统一地域/教育体系约束。若技能被更广泛使用,该要求会强制特定语言和教材规范,而没有提供按地区、学校或用户偏好调整的机制。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and the entire guide are written in Chinese, and the specification uses mandatory language throughout without offering any user opt-in or alternative locale. Under the policy criteria, forcing a specific language is a natural-language locale violation unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents all operational guidance in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow explicitly instructs the agent to retrieve information from external websites and collect source URLs, which expands the skill from local courseware generation into networked research and data acquisition. This increases the attack surface through prompt-injection from retrieved pages, privacy leakage via outbound requests, and behavior that is broader than the manifest suggests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The workflow introduces 3D/GLB/three.js production paths that materially extend the skill beyond single-file HTML/SVG courseware generation. Undeclared support for external assets and richer rendering pipelines can enable unexpected dependency loading, larger trust boundaries, and hidden execution paths not reviewed under the stated skill scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and generated report strings are entirely in Chinese, and the rules explicitly require a Chinese interface declaration. This suggests the skill enforces a specific language/locale without user opt-in or an explicit statement that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The zh_lang rule requires HTML to contain lang="zh" and prescribes as the fix. This is a natural-language policy constraint that forces a specific locale rather than offering a configurable or context-dependent language choice.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bundle_3d.py (reported line 116)May include surrounding context.

python
# ---- 4. 语法自检(node)----
import subprocess
r = subprocess.run(['node', '--check', '_three_bundle.js'], capture_output=True, text=True)
print('node --check:', 'PASS' if r.returncode == 0 else 'FAIL\n' + r.stderr[:500])

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill reference content is written in Chinese and presents instructional guidance only in that language. Under the policy rule, a language-specific constraint should either be optional for the user or clearly justified as a region- or locale-specific skill, which is not stated here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The workflow mandates copying from a specific local filesystem path and using a local template file as a required baseline. For a courseware-creation skill, hard dependence on developer-local paths is an implementation capability that is not justified by the stated educational content purpose and may not generalize to user environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code conditionally creates or overwrites the path provided after --report using open(..., 'w'), which is a file write operation. While the CLI usage mentions the flag, there is no explicit warning, confirmation, or nearby user-facing disclosure that the target file will be written/overwritten.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for producing single-file interactive HTML courseware, but this helper script also invokes an external runtime via subprocess. Launching a local executable is a stronger capability than ordinary file transformation and is not obviously required by the stated educational-content purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.