Back to skill

Security audit

个人技能工坊

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language skill-building assistant with an optional offline audit/evaluation script, and I did not find artifact-backed evidence of hidden exfiltration, destructive behavior, or deceptive persistence.

Install this only if you want a Chinese-language assistant that can help create or revise local skill files and validation artifacts. Review generated briefs, experiment records, and reports before sharing because they may summarize user materials or workflow details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个面向用户的“技能制作/升级助手”,核心在交互收集材料、补全缺口、形成或迭代 SKILL,并结合审计与实测验证。实际代码则是一个本地 CLI 工具,围绕现有技能目录和测试工件做静态审计、计划生成和结果评估。它读取/写入 JSON、遍历文件系统、检查 markdown/frontmatter/链接/密钥形状、计算文件和目录哈希、校验 suite/run schema,并基于已保存的响应文本做断言评估。没有任何创建或编辑 SKILL 内容、与用户问答、吸收补充材料、推导缺失内容的实现。因此主用途发生了实质偏移:从“交互式技能创建/升级”变成“离线审计与实验评估工具”。虽然声明中提到结构审计、逐轮实测和覆盖台账,和代码部分功能相关,但这些在代码中成了全部核心功能,而声明中的核心制作能力完全缺失,构成明显描述-行为不一致。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/toolkit.py (reported line 46)May include surrounding context.

python
r"\s*[:=]\s*['\"]?[A-Za-z0-9_./+=-]{16,}"
    )),
)
TEXT_SUFFIXES = {".md", ".txt", ".json", ".yaml", ".yml", ".toml", ".env"}
IGNORED_HASH_DIRS = {"__pycache__", ".pytest_cache", ".mypy_cache"}
IGNORED_HASH_SUFFIXES = {".pyc", ".pyo"}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/toolkit.py (reported line 322)May include surrounding context.

python
r"\s*[:=]\s*['\"]?[A-Za-z0-9_./+=-]{16,}"
    )),
)
TEXT_SUFFIXES = {".md", ".txt", ".json", ".yaml", ".yml", ".toml", ".env"}
IGNORED_HASH_DIRS = {"__pycache__", ".pytest_cache", ".mypy_cache"}
IGNORED_HASH_SUFFIXES = {".pyc", ".pyo"}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description and usage instructions are written in Chinese and do not state that other languages are supported or that the user may choose their preferred language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill instructs reading user materials, creating files, preserving artifacts outside the skill directory, and references use of tools and possible external validators, but it does not declare any explicit tool scope or permission boundaries. That creates an overprivilege/ambiguity risk: a host may expose broader file or network capabilities than are actually needed, increasing the blast radius if the skill is misused or if embedded content is adversarial.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing display name, description, and default prompt are all written in Chinese, which indicates a fixed language/locale presentation without any visible opt-in or explanation that this skill is region-specific. The policy requires either user choice or a clearly documented justification for a locale constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The default prompt uses broad natural-language activation text ('使用 $personal-skill-builder 创建或升级个人技能') combined with permissive behavior such as proactive inference and continuing with reversible defaults. This can cause the skill to activate in situations where the user did not clearly intend a skill-building workflow, increasing the chance of unintended data collection, overreach, or execution of a more powerful workflow than expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON manifest repeatedly specifies outputs such as "中文 Markdown", "简体中文", or "中文平实表达" as required behavior in many case definitions. Because these locale constraints are embedded as mandatory instructions rather than offering a user choice or documenting a justified region-specific scope, they constitute a natural-language language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational instructions exclusively in Chinese, which can impose a language constraint on users without offering an alternative or opt-in. Under the policy rule, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file specifies the output as "简体中文 Markdown 卡片," which imposes a specific language/locale choice. Under the policy, forcing a language without offering user choice or documenting a justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest template includes empty trigger_examples and non_trigger_examples arrays, providing no concrete activation phrases or exclusion examples. That creates an ambiguous trigger specification and increases the risk that downstream skills built from this template will define invocation behavior too broadly or inconsistently.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains all user-facing guidance in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. That can violate language/locale policy when a skill implicitly forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill guidance is written in Chinese and does not indicate that language is optional or selectable by the user. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to maintain and update assets/session-template.json creates an implicit persistence mechanism for user-provided information without any user-facing disclosure, consent, retention boundary, or minimization rule. In a skill explicitly designed to absorb supplemental user information across turns, this increases the risk of silently storing sensitive personal or workflow data beyond what the user expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L054 includes the default 采用简体中文输出 with the basis 当前交流语言,未指定其他语言, which imposes a language choice by default rather than offering an explicit language selection. This is a natural-language policy issue because it can force a locale/language behavior without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill guidance is written only in Chinese and includes no statement that the language is optional, selectable, or limited to a China-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains user-facing error messages in Chinese, and the CLI description/help text elsewhere in the file is also Chinese-only. Because the tool does not offer a language choice or explain a justified locale restriction, it appears to force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The command help text and status messages shown to users are Chinese-only. Under the policy, forcing a single language in user-facing text without offering a choice or documenting a justified locale-specific scope is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s natural-language content describing the skill is entirely in Chinese, which can amount to forcing a specific language on users without opt-in. The policy allows locale constraints when clearly documented and justified, but this changelog does not state that the skill is region- or language-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.