Back to skill

Security audit

Cn Emoji Translator

Security checks for vulnerabilities and agentic risk

Overview

This is a simple emoji translation skill with no evidence of hidden access, persistence, network use, or unsafe behavior.

Install only if a Chinese-language emoji translator fits your needs. It appears to run locally without network access or dependencies, but non-Chinese users may find the documentation and CLI messages harder to use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/emoji_translator.py (reported line 37)May include surrounding context.

python
"学习": "📚",
    "运动": "🏃", "跑步": "🏃", "游泳": "🏊", "唱歌": "🎤", "跳舞": "💃",
    
    # 时间
    "早上": "🌅", "中午": "☀️", "晚上": "🌙", "今天": "📅", "明天": "📅",
    "周末": "🗓️", "假期": "🏖️", "生日": "🎂", "新年": "🧧",
    
    # 人物
    "男人": "👨", "女人": "👩", "孩子": "👶", "老师": "👨‍🏫", "医生": "👨‍⚕️",
    "朋友": "👯", "家人": "👨‍👩‍👧‍👦",
    
    # 英文关键词
    "love": "❤️", "happy": "😊", "sad": "😢", "cool": "😎", "fire": "🔥",
    "ok": "👌", "yes": "✅", "no": "❌", "good": "👍", "bad": "👎",
    "cat": "🐱", "dog": "🐶", "heart": "❤️", "star": "⭐", "sun": "☀️",
}

# Emoji -> 文字描述映射
EMOJI_TO_TEXT = {
    "❤️": "[爱心]", "😊": "[微笑]", "😄": "[开心]", "😂": "[笑哭]",
    "😢": "[难过]", "😠": "[生气]", "😡": "[愤怒]", "😮": "[惊讶]",
    "�

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language descriptions, comments, error messages, and CLI help text exclusively in Chinese, including the title and argument help strings. Under the policy rule for language/locale constraints, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill name, description, usage guidance, and examples are written in Chinese, but the document does not indicate that the skill is region-specific or provide any user opt-in for language preference. This can violate language/locale policy expectations when skills are expected to accommodate user choice rather than implicitly forcing a language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.