Back to skill

Security audit

PC Build Assistant

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed PC-building advisor with local catalog scripts; it has data-quality caveats but no hidden credential access, persistence, or unsafe execution.

Before installing, treat this as a China-market desktop PC advisory skill: verify current local prices, stock, warranty, and exact SKUs before buying. Be cautious with server/NAS/workstation case suggestions and with FPS numbers, because some FPS rows are prediction-based rather than measured benchmarks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The public description presents the skill as a PC-building advisor, but the bundled behavior apparently includes local file validation/normalization, reading from stdin or arbitrary file paths, and writing normalized output for import workflows. Even if intended for catalog handling, that undisclosed capability expands the attack surface and can be abused for unexpected local file processing, path-based data access, or generating outputs outside the user’s expectations.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
This entry is a '4U服务器机箱', which is directly in the excluded category of server procurement. Its inclusion strongly indicates the skill can support server-hardware recommendations contrary to the manifest's stated limits.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
This is another explicit '服务器机箱' entry, which directly conflicts with the manifest's instruction not to use the skill for server procurement. The dataset therefore enables a forbidden recommendation domain.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The item is labeled '4U ... 服务器机箱', which is clearly server hardware and outside the manifest's allowed desktop PC building scope. This is a direct description-behavior mismatch because the skill's bundled data supports excluded recommendations.

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill instructs the agent to read multiple local reference files and to search current market prices when offline data is stale or the user requests real-time pricing, but it does not declare any explicit tool scope or allowed-tools boundaries. That creates an authorization and transparency gap: a host may permit broader file_read or network access than the skill actually needs, increasing the chance of unintended data exposure or uncontrolled outbound requests.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
This YAML manifest-like data file presents metadata and content in Chinese only, starting with the title and note fields, but does not document that the dataset is intentionally limited to Chinese-language users or a China-specific workflow. Under the language/locale policy, forcing a specific language without opt-in or explicit scope can be a natural-language policy violation.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest says the skill should not be used for laptops or server procurement, implying its data and recommendations should stay within desktop PC building. This file includes server-oriented products such as a '全塔服务器空机箱', which broadens the recommendation corpus beyond the declared desktop-only scope.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
NAS enclosures are purpose-built storage/server cases and are not ordinary desktop PC cases within the manifest's stated desktop-build domain. Their presence creates a mismatch between the skill's advertised desktop planning role and the actual inventory it can draw from.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
This entry is explicitly an '铝制外壳NAS', which belongs to NAS/server hardware rather than standard desktop PC build planning. That makes the available recommendation space broader than what the manifest claims.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
This entry is labeled '双路服务器机箱', which is a server procurement category rather than budget desktop PC build planning. Including such hardware in the skill's knowledge base can cause the assistant to recommend products outside its stated purpose.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The product is explicitly described as a '工作站机箱', which extends the skill into workstation/server-adjacent procurement rather than ordinary desktop PC building. That is a semantic mismatch with the manifest's explicit prohibition on server procurement use.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The entry is a 'NAS机箱', which is specialized infrastructure/storage hardware rather than mainstream desktop case guidance. This expands the skill's actual recommendation corpus beyond the stated desktop-use boundary.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
This record is explicitly described as a '全塔服务器工作站机箱', which is outside a desktop-focused skill whose manifest says not to use for server procurement. Including it creates a material mismatch between claimed scope and available recommendations.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
A NAS case is specialized storage-oriented hardware, not standard desktop build guidance. Bundling it in this desktop-PC skill broadens the actual behavior and recommendation surface beyond what the manifest says the skill is for.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The record explicitly says '服务器版', placing it outside the skill's declared desktop-only recommendation purpose. This broadens the skill's effective recommendation capabilities into an excluded hardware category.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The file declares that only exact-source FPS samples may be listed, yet the stored benchmark rows are labeled as public prediction samples. This creates a data integrity mismatch that can cause the assistant to present inferred performance as measured evidence, misleading users making hardware-buying decisions.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
This YAML consistently defines primary labels and presets in Chinese, including entries such as game names and preset descriptions, while providing no natural-language indication that the dataset is China-specific or that users may opt into another language. That creates a locale policy concern because the file appears to impose a single language by default rather than documenting a justified regional scope.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The sample requirements prohibit inferred FPS data and require direct same-game, same-resolution, same-preset samples, but the actual benchmark inventory uses prediction-based samples. This contradiction undermines trust controls and can propagate fabricated precision into recommendations, especially when users rely on the assistant for budget-sensitive build planning.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The manifest scope and source policy are written only in Chinese, which imposes a specific language/locale on users or downstream systems reading this skill metadata. The file does not offer a language choice or explain that the skill is intentionally region-specific, so this is a natural-language locale policy concern.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This markdown file presents all operational guidance exclusively in Chinese, and nowhere indicates that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file repeatedly instructs the agent to write the final response in English and to rewrite non-model-name text in English. While the activation section considers explicit user language choice, these lines impose English output as a hard requirement and can conflict with organizational language-choice policy if the user has not opted in clearly.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The unconditional instruction to 'Reply in English' in the Scope section can conflict with user language preference and may cause the skill to ignore later user requests for another language. In this skill context, that is primarily a policy and usability issue rather than a direct security exploit, but rigid output-language forcing can still lead to unsafe agent behavior if it overrides higher-priority user or system instructions.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The title and document content are entirely written as a Chinese-only instruction set, indicating the skill is intended to operate in Chinese by default. There is no natural-language indication that users may choose another language or that the locale restriction is optional or justified as region-specific.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
This markdown file contains natural-language instructions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The entire skill is written as Chinese-only operational guidance, with no indication that users may choose another language or that the skill is restricted to a Chinese-language or region-specific environment. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Static analysis

No suspicious patterns detected.