Back to skill

Security audit

ZDAT Crawl Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly harmful, but it asks for broad automated monitoring and alerts while the included code is only a partial scaffold.

Review this before installing if you plan to rely on it for monitoring. Configure exact keywords, sources, schedules, output files, and alert recipients, and verify the crawl and alert paths work before treating it as protective. Do not enable cron-style scheduled runs or enterprise-message pushes unless you intentionally want ongoing external monitoring under those settings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a broad intelligence-gathering and monitoring skill that encapsulates external search/crawl tools and performs scheduled collection, classification, and warning. The supplied code chunk is much narrower: it reads local schedule/keyword YAML files, gets a threshold and risk keyword list, and prints a status line for each keyword. The actual event counting is explicitly unimplemented (count = 0 # TODO), and there is no crawling, search, platform access, persistence, classification, or outbound alert push. While negative-alert checking is related to the declared theme, the implemented behavior is only a stubbed reporting/check script and does not accurately represent the larger declared functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description promises a fairly complete intelligence-gathering pipeline: keyword monitoring, multi-platform collection, auto-archival and categorization, negative-risk warning, and scheduled fetching through specific wrapped tools. The supplied code is only a partial scaffold. Its operative behavior is limited to reading keywords from a YAML file and printing simulated search actions. The search function is explicitly a mock/stub with a TODO for future integration. Although there are helper functions for simple classification and deduplication, they are not used in the execution flow, and there is no persistence/archive logic, no schedule handling, no alerting, and no evidence of blogwatcher integration. This is a material description-versus-behavior mismatch because the implemented primary capability is only a skeleton runner, not the described functional skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises automation that can read environment values and files, but it does not declare an explicit tool or permission scope. In agent systems, missing scope boundaries can cause over-broad access at runtime, making it easier for the skill to read local data or secrets beyond what a user would reasonably expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description omits a clear warning that it may perform third-party monitoring, collect external content, write to files like Excel, and push alerts to enterprise messaging. Without upfront disclosure and consent, users may trigger actions with privacy, compliance, or operational consequences they did not intend, especially in a monitoring/intelligence-gathering context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Broad trigger phrases such as general requests about monitoring or intelligence collection can cause accidental activation in unrelated contexts. Because this skill is framed as performing external collection, scheduled crawling, and downstream actions, ambiguous activation increases the risk of unintended data gathering or writes without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script claims to perform alert push notifications, but it only prints to stdout and never sends any notification. In a monitoring/negative-warning skill, this can create a dangerous false sense of protection: operators may believe alerts are being delivered when critical negative events are silently missed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code does not count negative keyword occurrences at all and hardcodes count = 0, so alerts can never trigger regardless of real-world conditions. For an intelligence/negative-monitoring skill, this completely defeats the detection purpose and can allow important signals to be missed without any obvious failure indication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module description and all user-facing status messages are written in Chinese, which indicates the skill is effectively fixed to a specific language. There is no opt-in, language selection mechanism, or documented justification that this skill is intended only for Chinese-language users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring describes the script entirely in Chinese and the user-facing console messages are also hardcoded in Chinese, indicating a fixed language choice. Under the stated policy, forcing a specific language without user opt-in or a documented justified regional scope is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The script reads files from a path derived from the WORKDIR environment variable and then opens YAML configuration files from that location. Although this is not inherently unsafe, it accesses user/workspace data without any explicit warning in comments, docstrings, or user-facing output about which files are being read.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.