Back to skill

Security audit

Training Swarm

Security checks for vulnerabilities and agentic risk

Overview

This training assistant is coherent in purpose, but it under-discloses persistent local file writes and outbound WeChat-style reminder behavior.

Review before installing. Use it only if you are comfortable with a training skill that may create persistent files in your home directory and may use networked reminder channels. Require explicit confirmation before writing training records or sending reminders, especially where employee progress, assessments, or personal data are involved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill manifest declares only file-read permission, but the documented initialization workflow creates directories and writes multiple files under ~/.workbuddy/tasks. This is a real capability mismatch that can mislead users and security controls, enabling unauthorized persistence and local state modification beyond the declared permission model.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is described as a training and knowledge-management assistant, but its behavior includes local workspace creation, archival, and persistent task logging that are not reflected in the manifest description. This creates deceptive functionality scope, making operators less likely to anticipate storage of potentially sensitive training, personnel, or assessment data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The when_to_use field includes broad, common trigger phrases such as 培训, 出题, and 知识管理, which can cause accidental invocation during ordinary conversation. Overbroad activation increases the chance the skill runs in unintended contexts, potentially accessing files or sending networked reminders based on unrelated user content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger section provides a wide keyword list without activation boundaries, exclusions, or examples of when not to invoke the skill. In a skill with file-read and network-access permissions, ambiguous activation increases the risk of unintended processing of user data and unwanted outbound actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

This duplicate finding points to the same persistent workspace creation behavior: making ~/.workbuddy/tasks and writing multiple logs that survive the current session. Persistent artifacts can be later accessed, correlated, or misused, and the risk is elevated here because the skill handles training and assessment workflows that may include employee-related data.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
TASK_NAME="training-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 培训赋能

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

This duplicate finding points to the same persistent workspace creation behavior: making ~/.workbuddy/tasks and writing multiple logs that survive the current session. Persistent artifacts can be later accessed, correlated, or misused, and the risk is elevated here because the skill handles training and assessment workflows that may include employee-related data.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
TASK_NAME="training-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 培训赋能

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises proactive WeChat push reminders but does not warn users about outbound messaging, recipient handling, or what data may be transmitted. Because reminders are tied to learning progress and assessments, this can expose personal or performance-related information through external channels without adequate transparency or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The primary description is presented entirely in Chinese and the rest of the skill instructions are effectively Chinese-only, but there is no statement that the skill is region-specific or that users may choose another language. This can be a natural-language policy issue when a skill implicitly forces a locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.