Back to skill

Security audit

程序员变量名生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple variable-name formatter with no executable code, external access, persistence, or sensitive data handling.

Before installing, expect this skill to answer naming requests in a fixed Chinese two-line format. It does not appear to run code or access data, but users who prefer English or flexible formatting may want clearer language options.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L003 将触发场景描述为“用户输入中文或英文关键词,要求生成变量名、函数名、API 命名等”,这类条件覆盖面很广,可能与日常编程求助或普通命名讨论重叠。文档没有给出明确的触发短语、边界条件或负例,导致何时应激活该技能不够清晰。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L011 规定“输出格式(固定,不可更改)”,且全文规范均以中文说明输出样式,没有提供语言/locale 选择。这会造成技能在未征得用户同意时默认强制使用特定语言,符合语言/地区策略违规特征。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.