Back to skill

Security audit

lqs-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed code-artifact generator, but it gives agents under-scoped authority to write generated code files and persistent patterns.

Install only for an LQS repository where you are comfortable reviewing generated PHP, SQL, and template changes before they are written. Require explicit per-file approval using canonical in-repo paths, do not allow absolute or parent-directory targets, review migration rollback behavior carefully, and do not let session-derived patterns become trusted project context without maintainer review.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
schemas/render_plan.schema.json:13
Finding

Unrestricted RenderPlan Targets Permit Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
templates/template_pack.blueprint.json:21
Finding

Raw Placeholder Substitution Enables Generated PHP, SQL, and Markup Injection

Content
View full analysis
display(); } protected function listAjaxIteration() { return function ({{model_class}} $item) { {{list_item_mapping}} return $item; }; } protected function getSearchWhereParam() { {{search_where_logic}} } protected function formatKey($key, $value) { {{format_key_logic}} } protected function getLogDesc(): string { return '{{log_desc}}'; } protected function getDesc($query): string { {{desc_logic}} } ``` `templates/generated/admin_model.txt:6-20`: ```php class {{Entity}}Model extends \Illuminate\Database\Eloquent\Model { protected $table = '{{table}}'; protected $primaryKey = '{{pk}}'; public $timestamps = {{timestamps}}; protected $fillable = [ {{fillable_lines}} ]; protected $casts = [ {{casts_lines}} ]; {{relations_block}} } ``` `templates/generated/admin_index_view.txt:14-59`: ```html
{{page_title}}
... {{search_fields_bl ...[truncated 3272 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
templates/generated/migration_create_table.txt:17
Finding

Unsafe JSON Embedding Allows PHP Source Injection in Generated Migrations

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
implementation_runbook.md:5
Finding

Session-Derived Inferences Can Poison Persistent Agent Context

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (30)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

File system write capability is not justified by the described purpose of the skill, which is generation of drafts, specs, render plans, and preview diffs. A model-directed write step increases the risk of arbitrary file modification, accidental overwrites, or abuse through crafted input that influences target content or destinations, especially if downstream tooling treats the prompt as authority.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt explicitly instructs writing files when approval is given, which exceeds the manifest’s stated scope of a manual, preview-oriented artifact generator. Even with an approval gate, embedding file-write behavior in the skill creates an operational side effect that can turn prompt output into unauthorized or unintended repository changes if an integrating agent honors it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill is a prompt/schema/template-driven artifact generator and explicitly states it does not execute code or run migrations. This template is specifically a runnable PHP migration that inserts and deletes records in the permissions table via database calls, which goes beyond a purely documentation/spec-generation role and conflicts with the stated no-migrations scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says this skill is an artifact generator and explicitly states it does not execute code or run migrations automatically. This template defines executable migration methods that issue CREATE TABLE and DROP TABLE statements via \DB::statement, which is behavior beyond pure artifact generation if used as part of the skill's code path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation phrases include very generic developer requests such as "generate controller", "generate model", and "preview diff", which can unintentionally trigger this skill during unrelated coding tasks. Because the skill is prompt-driven and consumes free-text user input, accidental invocation could steer an agent into generating artifacts or workflow steps outside the user's intended context, increasing the risk of incorrect changes or prompt-scope confusion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The domain glossary defines core workflow terms exclusively in Chinese (e.g. 后台, 列表, 保存, 删除, 预览), which indicates a language-specific operating assumption in the skill context. The file does not offer any language preference, opt-in, or justification that this skill is intended only for Chinese-language users or a China-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSON content is entirely written in Chinese, including feature descriptions, constraints, assumptions, and ambiguities, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-language context. This creates a natural-language policy concern because it effectively imposes a locale/language choice without opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented workflow describes automatic retrieval and transformation of Google Doc content from a link, directly contradicting the skill's declared manual-run, no-auto-fetch behavior. In a prompt-driven artifact generation skill, this inconsistency increases the risk of unauthorized external data ingestion, accidental collection of sensitive document content, and operator misunderstanding about what the skill is permitted to do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example contract explicitly documents taking a public Google Doc link and fetching the document body, which conflicts with the stated skill boundary that it does not fetch external documents automatically. This kind of contract/manifest mismatch is dangerous because downstream agents or operators may enable network retrieval behavior that bypasses expected trust boundaries, privacy review, or data-handling controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and the entire runbook are written in Chinese, presenting the skill instructions in a single enforced language. Under the policy, language constraints should either offer a user choice or be clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a prompt-driven artifact generator that does not execute code or run migrations. This runbook explicitly includes 'migration' in the generated TemplatePack and sets a migration table-prefix convention, which expands the skill behavior into database-migration artifact generation beyond the manifest's stated limitation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · patterns/project_pattern_profile.json (reported line 77)May include surrounding context.

json
"migration_rules": {
    "prefix": "typecho_",
    "must_have": ["up", "down"],
    "execution": "generate only, no auto run"
  },
  "known_exceptions": [
    {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The prompt begins in Chinese and frames the skill as a Chinese-language requirements analyzer, which implicitly constrains language/locale behavior. There is no indication that the user may choose another language or that this restriction is required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L01 states the role entirely in Chinese and establishes the skill behavior in a fixed language, with no indication that the user can choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s natural-language instructions are entirely in Chinese, beginning with '你是规格解析器。', which imposes a specific language context without offering the user any language or locale choice. Under the policy, forcing a language without opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill prompt is written in Chinese and does not indicate that the language is configurable or based on user preference. Per the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L01 states the skill role entirely in Chinese, and the file provides no option for user language preference or any justification that this is a region-specific tool. This creates a natural-language policy concern because it implicitly constrains the skill to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Labeling the prompt as a 'write executor' materially conflicts with the manifest’s preview-focused workflow and signals an operational role the skill is not supposed to have. This mismatch can cause integrators or agents to grant broader capabilities than intended, weakening trust boundaries and increasing the chance of unsafe side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file begins with Chinese-only instructions ('你是 LQS Skill 的写入执行器') and the rest of the skill content is also written entirely in Chinese. This creates a language policy concern because it imposes a specific language/locale without any opt-in or documented justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quickstart describes the skill entirely in Chinese and explicitly positions it as a natural-language analysis skill, which implies a language expectation for user interaction. There is no indication that users may choose another language or that the Chinese-only presentation is a justified region-specific requirement, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s title and substantive instructions are presented in Chinese, and nowhere in the document is there an opt-in, alternate language option, or justification that the skill is region-specific. Under the policy rule, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header comment explicitly frames the file as generation-only and non-auto-executing, yet the class body includes \DB::statement($sql) in both up() and down(). That is a direct contradiction between the file's stated intent and what the code does when executed.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · templates/generated/migration_create_table.txt (reported line 5)May include surrounding context.

text
/**
 * Auto-generated migration template from LQS project patterns.
 * Note: generate only, do not auto-execute.
 */
class {{class_name}}
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs an irreversible database table deletion via DROP TABLE IF EXISTS, but the file provides no user-facing confirmation, prompt, or explicit warning about the destructive action. Although there is a brief comment that custom down logic is optional, it does not disclose to users that rollback will delete the table.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON manifest contains multiple natural-language strings in Chinese, including field labels and assumption/ambiguity text, but does not indicate that the skill is intentionally region-specific or provide any user opt-in for language/locale. Under the policy rule for natural-language constraints, hard-coding a specific language without justification can be a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.