Back to skill

Security audit

Summarize

Security checks for vulnerabilities and agentic risk

Overview

The skill's normal summarization behavior is coherent, but its published installers execute mutable remote GitHub scripts and the Unix updater can delete an existing installation before a replacement is validated.

Do not use the published curl|bash or iwr|iex commands unless you trust the GitHub repository state at install time. Prefer installing from the reviewed local package or a pinned, checksum-verified release, and back up any existing summarize skill directory before updating. The runtime skill behavior is otherwise disclosed: summaries are read-only by default, and saved handoffs are written only when explicitly requested.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
sutras.yaml:48
Finding

Mutable Remote Installers Are Downloaded and Executed Without Verification

Content
View full analysis
Remediation
View remediation
install.sh" | sha256sum --check - less install.sh bash install.sh ``` 6. Use Authenticode or another appropriate signing mechanism for the PowerShell installer and verify the signature before execution. 7. Prefer installation from the reviewed local package or a trusted package manager that verifies signed, immutable releases. 8. Configure CI to reject distribution metadata containing pipe-to-shell or download-to-`Invoke-Expression` patterns. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:41
Finding

Unix Update Fallback Deletes the Existing Installation Before a Replacement Is Validated

Content
View full analysis
/dev/null || { cd "$HOME" && rm -rf "$INSTALL_DIR" && git clone "$REPO_SSH" "$INSTALL_DIR" 2>/dev/null || git clone "$REPO_HTTPS" "$INSTALL_DIR"; } ``` ### Technical Analysis If `git pull --rebase` fails for any reason, the fallback recursively deletes the existing installation before confirming that a replacement can be downloaded and validated. A pull can fail because of local modifications, repository corruption, network failure, authentication failure, divergent history, or upstream availability. These conditions do not justify deleting the existing installation. The replacement is cloned directly into the final path and is not pinned to a specific reviewed release or commit. There is no temporary staging directory, integrity check, content validation, or atomic swap. If both clone attempts fail, the user can be left without a functioning installation. Local modifications in the installation directory are irreversibly removed. Although `INSTALL_DIR` is generated from predefined user-level paths in this script, recursive deletion remains broader and more destructive than required for an update operation. ### Attack Path 1. A user runs the Unix installer while the Skill already exists. 2. `git pull --rebase` fails because of local changes, network disruption, authentication failure, repository state, or an intentionally induced upstream condition. 3. The fallback changes to the user's home directory and executes `rm -rf "$INSTALL_DIR"`. 4. The previously installed copy and any local changes are deleted. 5. The script attempts an SSH clone and then an HTTPS clone. 6. If cloning fails, the in ...[truncated 894 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (53)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · DESIGN-v10.md (reported line 102)May include surrounding context.

输出示例:

text
C1-ERR: 2项失败
  1. Bash: "git push origin master" → fatal: remote rejected (ENVR·第2次·未收敛)
     建议: 检查远程分支保护规则,或使用 --force-with-lease
  2. Read: "src/missing.ts" → Error: file not found (TOOL·第1次·已处理→后续补创建)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · DESIGN-v10.md (reported line 102)May include surrounding context.

输出示例:

text
C1-ERR: 2项失败
  1. Bash: "git push origin master" → fatal: remote rejected (ENVR·第2次·未收敛)
     建议: 检查远程分支保护规则,或使用 --force-with-lease
  2. Read: "src/missing.ts" → Error: file not found (TOOL·第1次·已处理→后续补创建)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个“总结/压缩/交接”技能,核心行为应是根据当前任务上下文生成摘要或保存交接信息。实际代码并不总结当前任务,也不生成任何摘要内容;它只是检查已保存 handoff 文件及 latest 指针是否合法,并把报告中的工作区元数据与当前 Git 分支/提交进行比对,判断该 handoff 是否过期或可验证。这属于 handoff 完整性/新鲜度检查工具,而非总结工具的直接实现。虽然它与‘交接’场景相关,且保持只读与声明不冲突,但其主要目的与声明的主要用途存在实质偏差,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个用于总结、压缩上下文和交接任务的技能行为,强调默认只读、仅特定情况下写入工作区。但实际代码并未实现任何总结、分析、提取任务状态或生成建议的逻辑;它是一个安装/更新脚本。脚本会探测 /.agents、/.codebuddy、/.claude、/.codex、~/.reasonix 等目录,决定安装路径,并执行 git pull、git clone,必要时 rm -rf 删除已有安装目录后重新克隆。这些都是远程拉取与本地文件系统修改能力,属于未在声明中体现的主要行为。虽然“安装 summarize 技能”可能与该技能相关,但该代码块的主用途与声明的技能功能本身明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向任务总结/交接的技能行为,而代码实际是发布资源一致性测试,与总结、提取任务状态、生成建议或按用户触发进行上下文压缩没有直接关系。该代码的主要目的明显不同:它检查 SKILL.md、manifest.json、若干 references 和 scripts 文件是否被 Git 跟踪。这属于仓库发布完整性验证和版本控制检查,是未在声明中体现的能力与资源访问范围。因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/CHANGELOG.md (reported line 152)May include surrounding context.

md
- 🗜️ **New: Session Condense (模块1)** — ≤5句关键摘要 + 文件清单 + 关键决策
- 📋 **New: Task Progress (模块2)** — 完成/待办/下一步 + 压力等级
- ⚡ **New: Error Self-Evolve (模块3)** — 5维分类 + 规则回测 + 全局/项目分流
- ✅ **Bilingual** — 中英双语技能描述,国际化支持

### v3.0.0 (2026-06-17)

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/install.sh (reported line 3)May include surrounding context.

sh
#!/bin/bash
# summarize skill — multi-platform one-line installer
# curl -sL https://raw.githubusercontent.com/gtbwpkwjnb-alt/summarize-skill/master/install.sh | bash

set -e

Chaining Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The chained fallback logic combines update failure, directory deletion, and recloning in a single command path. This makes destructive actions occur automatically on transient git errors and increases the blast radius of mistakes, especially because the target path is under the user's home directory and may contain customizations or data.

Content

Scanner excerpt · scripts/install.sh (reported line 50)May include surrounding context.

sh
echo "   Already installed at $INSTALL_DIR"
    echo "🔄 Updating to latest version..."
    cd "$INSTALL_DIR"
    git pull --rebase 2>/dev/null || { cd "$HOME" && rm -rf "$INSTALL_DIR" && git clone "$REPO_SSH" "$INSTALL_DIR" 2>/dev/null || git clone "$REPO_HTTPS" "$INSTALL_DIR"; }
else
    echo "   Cloning into $INSTALL_DIR ..."
    mkdir -p "$(dirname "$INSTALL_DIR")"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DESIGN-v10.md (reported line 152)May include surrounding context.

输出示例:

text
C1-TMO: 1项超时
  1. WebFetch: "https://api.example.com/data" → timeout (ENVR·重试1次仍失败·持续阻塞)
     建议: 检查网络连通性,或切换到离线数据源

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger design treats a very common phrase like “总结/summarize” as a broad activation signal across any platform, which can cause unintended invocation during normal conversation. In an agent environment, accidental activation can hijack the workflow, generate unsolicited summaries, or cause writes/export behavior if paired with permissive save semantics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The design hard-codes a platform-specific greeting requirement (好的老板) as a rule violation if not used, which overrides user preference and can manipulate outputs independently of task needs. This creates prompt-level behavioral coercion, reduces reliability, and may produce inappropriate or policy-conflicting responses in multilingual or professional contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation section defines independent-word triggers (总结/summarize) but does not provide scope limits, exclusions, or examples of non-invocation. That ambiguity increases the chance that the skill fires on incidental mentions, quoted text, translations, or meta-discussion, leading to unintended behavior and possible unauthorized workspace writes in save mode.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill name, design principles, usage commands, and installation guidance are all presented in Chinese, and the invocation phrases are Chinese-centric (for example 总结, 总结进度, 复盘) with no indication that other languages are supported or that Chinese is required for a region-specific reason. This creates a natural-language locale constraint without user opt-in, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
## 安装

将本目录放在 Codex 可发现的 skills 路径(通常为 `~/.codex/skills/summarize`),或使用仓库内的安装脚本。安装后按上述表达请求即可。

## License

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
## 安装

将本目录放在 Codex 可发现的 skills 路径(通常为 `~/.codex/skills/summarize`),或使用仓库内的安装脚本。安装后按上述表达请求即可。

## License

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill text explicitly instructs use of file reads, shell commands, and conditional file writes, but it declares no tool scope or allowed-tools restriction. In an agent environment, this creates unnecessary capability ambiguity: the skill may be invoked with broader permissions than users expect, increasing the chance of unintended repository inspection or workspace modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file records and reinforces a mandatory opening phrase for new sessions ("好的老板"), which attempts to constrain future assistant behavior independent of the user's actual preferences or the normal instruction hierarchy. Even though it appears in an error log, it operationalizes a standing behavioral requirement that can create prompt-steering, role conditioning, and reduced responsiveness to user intent.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The required subordinate-style phrase ("好的老板") semantically pressures the model into a deferential role relationship that may affect later instruction handling and increase susceptibility to hierarchy confusion. In the surrounding context, the file explicitly frames failure to emit the phrase as a policy violation and prescribes sentinel reinforcements, making the steering stronger rather than incidental.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains natural-language statements that describe the skill behavior as locked to English output with no ability to switch to Chinese. Under the policy, forcing a specific language without user opt-in is a reportable locale/language violation unless it is clearly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document content is entirely in Chinese, including headings and operational descriptions, with no indication that language choice is optional or that the skill is region-specific. This creates a natural-language policy concern because it effectively imposes a locale on users without explicit opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file documents multiple broad natural-language trigger phrases such as “总结”, “复盘”, and “summarize”, which are common in ordinary conversation and can cause the skill to activate when the user did not explicitly intend to invoke it. Because this skill can read project context and, in some modes, write a handoff file when a related phrase is used, accidental activation can expose context or alter workspace state unintentionally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that the language is optional, user-selected, or required for a specific regional/compliance reason. Under the policy rule for natural-language violations, this constitutes a locale/language constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file explicitly marks PaddleOCR as preferred for Chinese and states that Tesseract should not be used for Chinese, but it does not clarify that this skill is intentionally limited to Chinese-language documents or offer any language/locale opt-in. Because this is natural-language guidance in a markdown file, it can amount to a locale policy constraint that is undocumented from the user's perspective.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · harvests/sess_tools.md (reported line 14)May include surrounding context.

md
- .zcode/v2/config.json — DeepSeek baseURL 还原
- .agents/skills/headroom/ — 已删除
- .agents/skills/sub-agents-tmp/ — 已删除
- .agents/skills/agent-reach/SKILL.md — 描述精简
- .agents/skills/bibi/SKILL.md — 描述精简
- .agents/skills/multiai/SKILL.md — 描述精简

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · harvests/sess_tools.md (reported line 15)May include surrounding context.

md
- .agents/skills/headroom/ — 已删除
- .agents/skills/sub-agents-tmp/ — 已删除
- .agents/skills/agent-reach/SKILL.md — 描述精简
- .agents/skills/bibi/SKILL.md — 描述精简
- .agents/skills/multiai/SKILL.md — 描述精简

## 完整错误列表

Static analysis

No suspicious patterns detected.