Back to skill

Security audit

Skills Summarize Audit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only auditing and recommendation helper, with sensitive local scans disclosed and mostly gated by explicit user action.

Before installing, be aware that this skill can help an agent read local skill/plugin directories, MCP config metadata, and, when you explicitly run the usage-signal collector, agent session transcripts. Use it only when you are comfortable auditing those local paths, avoid broad all-client scans unless needed, and review reports before following any suggested install, update, archive, or uninstall action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Rogue AgentSelf-Modification, Session Persistence
Findings (127)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Git status checks and external git subprocess execution go beyond a plain documentation/recommendation role and introduce command-execution risk, even if intended read-only. Shelling out can leak repository metadata, touch unexpected paths through repository configuration, or create a misleading safety model when the skill says it does not actively operate on the environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Git status checks and external git subprocess execution go beyond a plain documentation/recommendation role and introduce command-execution risk, even if intended read-only. Shelling out can leak repository metadata, touch unexpected paths through repository configuration, or create a misleading safety model when the skill says it does not actively operate on the environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Git status checks and external git subprocess execution go beyond a plain documentation/recommendation role and introduce command-execution risk, even if intended read-only. Shelling out can leak repository metadata, touch unexpected paths through repository configuration, or create a misleading safety model when the skill says it does not actively operate on the environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Git status checks and external git subprocess execution go beyond a plain documentation/recommendation role and introduce command-execution risk, even if intended read-only. Shelling out can leak repository metadata, touch unexpected paths through repository configuration, or create a misleading safety model when the skill says it does not actively operate on the environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Git status checks and external git subprocess execution go beyond a plain documentation/recommendation role and introduce command-execution risk, even if intended read-only. Shelling out can leak repository metadata, touch unexpected paths through repository configuration, or create a misleading safety model when the skill says it does not actively operate on the environment.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · platforms/codex.yaml (reported line 9)May include surrounding context.

yaml
# Codex 特有配置
codex:
  skills_dir: "~/.codex/skills/"
  config_file: "~/.codex/config.toml"
  # Codex 当前技能生态较新,外部信号可能不丰富,建议降低 Community 阈值
  community_min_stars: 5  # 默认100→降低到5(生态新)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The document instructs scanning local agent configuration files in user home directories, which can expose sensitive configuration details such as MCP server endpoints, commands, and environment variables if implemented without strict read-only scope and masking. Although the skill states env fields must be desensitized and the intent is audit-only, enumerating and parsing these files still increases the chance of credential leakage or overbroad local file access by downstream agents.

Content

Scanner excerpt · references/mcp-marketplaces.md (reported line 158)May include surrounding context.

text
~/.zcode/cli/config.json         # ZCode MCP
~/.claude.json                   # Claude Code MCP  
~/.codex/config.toml             # Codex MCP

提取规则

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/security-rules.yaml (reported line 59)May include surrounding context.

yaml
- id: "SEC-004"
    type: "supply_chain"
    severity: "HIGH"
    description: "curl | bash 远程脚本直接执行 — 需附带 SHA256 校验和"
    scope:
      files: ["README.md", "*.md"]
      patterns:

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/skill-registry.yaml (reported line 29)May include surrounding context.

yaml
- name: "summarize"
    version: "6.8.0"
    category: docs
    tags: ["summary", "session", "context", "token-tracking", "error-harvest", "self-evolve", "compress", "cross-agent"]
    description: "总结 → 错误收割·自进化·可逆压缩 | Summarize → error harvest·self-evolve·compress"
    source: "local"
    homepage: "https://github.com/gtbwpkwjnb-alt/summarize-skill"

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/skill-registry.yaml (reported line 30)May include surrounding context.

yaml
- name: "summarize"
    version: "6.8.0"
    category: docs
    tags: ["summary", "session", "context", "token-tracking", "error-harvest", "self-evolve", "compress", "cross-agent"]
    description: "总结 → 错误收割·自进化·可逆压缩 | Summarize → error harvest·self-evolve·compress"
    source: "local"
    homepage: "https://github.com/gtbwpkwjnb-alt/summarize-skill"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · install.ps1 (reported line 1)May include surrounding context.

text
# 分层测试 — T1/T2/T3 + T3 活性验证

> 验证 ④ 三级分层 + ④-a T3 活性验证逻辑

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · tests/README.md (reported line 1)May include surrounding context.

md
# 分层测试 — T1/T2/T3 + T3 活性验证

> 验证 ④ 三级分层 + ④-a T3 活性验证逻辑

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · tests/test-rollback-flow.md (reported line 1)May include surrounding context.

md
# 分层测试 — T1/T2/T3 + T3 活性验证

> 验证 ④ 三级分层 + ④-a T3 活性验证逻辑

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · tests/test-tier-classification.md (reported line 1)May include surrounding context.

md
# 分层测试 — T1/T2/T3 + T3 活性验证

> 验证 ④ 三级分层 + ④-a T3 活性验证逻辑

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · tests/test_evidence_contract.py (reported line 302)May include surrounding context.

python
"--zcode-config", str(local_tree / "missing-config.json"),
            "--agents-dir", str(local_tree / "missing-agents"),
            "--reasonix-dir", str(local_tree / "missing-reasonix"), "--json"]
    first = subprocess.run(args + ["--output", str(output)], capture_output=True, text=True, encoding="utf-8")
    assert first.returncode == 0, first.stderr
    initial = json.loads(output.read_text(encoding="utf-8"))
    assert initial["scope"] == "ecosystem"

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · tests/test_evidence_contract.py (reported line 307)May include surrounding context.

python
initial = json.loads(output.read_text(encoding="utf-8"))
    assert initial["scope"] == "ecosystem"
    assert initial["scan"]["mode"] == "full"
    second = subprocess.run(args + ["--baseline", str(output)], capture_output=True, text=True, encoding="utf-8")
    assert second.returncode == 0, second.stderr
    reused = json.loads(second.stdout)
    assert reused["scan"]["mode"] == "incremental"

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code explicitly requires Chinese characters in the UI short description and checks for multiple Chinese-language content requirements in SKILL.md. This is a natural-language policy violation because it hard-enforces a specific language/locale rather than offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 53)May include surrounding context.

md
## [8.2.2] - 2026-07-23

- config.yaml 顶部注明本文件为 Agent 行为约定配置、无脚本消费,并在 translation_refinement 块补 collect 脚本声明,三个脚本均有 script 声明。
- platforms/workbuddy.yaml 移除与只读底线矛盾的 write 权限;新增 platforms/README.md 说明平台文件仅记录平台特征、无脚本消费。
- 推荐档位术语统一为六档(保留/升级/替换/引入/共存/归档),修正 SKILL.md、config.yaml 注释与 recommendation-framework.md 中的"五档"误述。
- 合并 references/description-refinement.md 的 Forma 维度/权重/阈值至 description-quality.md 并删除原文件,消除双份事实源。
- SKILL.md 输出节与 report-template.md 接入 references/output-contract.md 事实状态契约引用。

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 53)May include surrounding context.

md
## [8.2.2] - 2026-07-23

- config.yaml 顶部注明本文件为 Agent 行为约定配置、无脚本消费,并在 translation_refinement 块补 collect 脚本声明,三个脚本均有 script 声明。
- platforms/workbuddy.yaml 移除与只读底线矛盾的 write 权限;新增 platforms/README.md 说明平台文件仅记录平台特征、无脚本消费。
- 推荐档位术语统一为六档(保留/升级/替换/引入/共存/归档),修正 SKILL.md、config.yaml 注释与 recommendation-framework.md 中的"五档"误述。
- 合并 references/description-refinement.md 的 Forma 维度/权重/阈值至 description-quality.md 并删除原文件,消除双份事实源。
- SKILL.md 输出节与 report-template.md 接入 references/output-contract.md 事实状态契约引用。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L03 describes the skill as being for Chinese users ('面向中文用户') and the outputs are defined in Chinese, but the file does not offer an alternative language mode or user opt-in. Under the policy, forcing a specific language without choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L21 states '支持自然语言请求' without defining constraints, examples of valid phrasing, or exclusion conditions. This can make activation ambiguous and increases the chance of unintended invocation from ordinary conversation rather than explicit skill commands.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill references scripts, file inspection, hashing, optional network-backed market research, and shell-style commands, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity where a host may grant broader file, network, or shell access than users expect from a 'default read-only' auditing skill, increasing the risk of overreach or accidental sensitive data access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states '面向中文用户' and the skill behavior is oriented toward Chinese output by default, which is a natural-language locale policy constraint. The file does not offer an explicit language choice or opt-in, so it appears to force a specific language/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction '默认简体中文' sets a mandatory default locale for generated content. Because no nearby text offers the user a language selection or opt-in, this is a policy-relevant language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Both the short description and default prompt specify Chinese output ('中文说明精炼' and Chinese-only instructions) with no indication that the user may choose another language. This is a natural-language locale policy concern because it imposes a language preference by default rather than offering an explicit opt-in or selection.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_analyze_project_profile.py:15

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_audit_skill_plugin_issues.py:21

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_collect_codex_display_candidates.py:25

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_evidence_contract.py:324

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_profile_output.py:10