Back to skill

Security audit

Skill Quality Checker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local checker, but its current reports can show fixed favorable scores even when the checks did not support them.

Review this carefully before installing. It does not appear to steal data or install a backdoor, but its assessment output is not trustworthy yet because the main report path can ignore real checker results and display fixed favorable scores. Use it only as a rough prototype, inspect any generated findings manually, and avoid relying on its star rating or pass/fail summary for security decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
assess.sh:170
Finding

Assessment Results Are Discarded and Replaced with Fabricated Scores

Content
View full analysis
"$report_file" << EOF # 技能评估报告:$skill_name ## 评估摘要 - **评估时间**:$(date '+%Y-%m-%d %H:%M:%S') - **评估方式**:静态分析(选项1 - 轻量) - **技能路径**:$skill_path ## 评估结果 > 报告生成中,需要完善评估模块... ## 下一步 1. 实现各个评估模块 (doc_checker.sh, code_analyzer.sh 等) 2. 完善报告模板 3. 添加评分计算逻辑 EOF log_success "报告已生成: $report_file" # 显示摘要 show_summary "$skill_name" "$report_file" } show_summary() { local skill_name="$1" local report_file="$2" echo "" echo -e "${CYAN}🔍 技能评估报告:$skill_name${NC}" echo -e "${BLUE}📊 综合评分:★★★★☆ (4.2/5)${NC}" echo -e "${BLUE}⏱️ 评估用时:$(($SECONDS))秒${NC}" echo -e "${BLUE}📁 技能路径:$skill_path${NC}" echo "" echo -e "${YELLOW}维度得分:${NC}" echo -e " 文档完整性:★★★★☆ (4.0/5)" echo -e " 代码规范性:★★★★★ (4.5/5)" echo -e " 配置友好度:★★★☆☆ (3.5/5)" echo -e " 维护活跃度:★★★★☆ (4.0/5)" echo "" echo -e "${YELLOW}⚠️ 发现问题:3个${NC}" echo -e "${GREEN}✅ 通过检查:21个${NC}" echo -e "${BLUE}📋 详细报告:$report_file${NC}" echo "" } ``` ### Technical Analysis The four evaluator scripts write their findings to temporary JSON files, and those file paths are passed into `generate_report`. Although the function stores the paths in `result_files`, it never reads, validates, aggregates, or reports their contents. Instead, the generated report contains a placeholder, while the terminal summa ...[truncated 1462 chars]
Remediation
View remediation
/dev/null; then log_error "Invalid evaluator output: $result_file" return 1 fi done ``` 2. Calculate the overall score from actual evaluator scores and configured weights. 3. Populate the report with the real issues and suggestions from each evaluator. 4. Remove all hard-coded scores, star ratings, issue counts, and pass counts. 5. Fail closed if an evaluator terminates unexpectedly, emits invalid JSON, or does not run. 6. Add automated tests using both safe and intentionally vulnerable fixture Skills. Verify that different inputs produce corresponding scores and findings. 7. Clearly distinguish incomplete assessments from successful assessments; never show a favorable score when aggregation has failed. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
assess.sh:22
Finding

Untrusted Skill Paths Permit Terminal and Markdown Output Injection

Content
View full analysis
&2 } assess_skill() { local skill_path="$1" local skill_name skill_name=$(basename "$skill_path") log_info "评估技能: $skill_name" log_info "技能路径: $skill_path" ``` ```bash local skill_name skill_name=$(basename "$skill_path") local timestamp timestamp=$(date '+%Y-%m-%d_%H-%M-%S') local report_file="${REPORT_DIR}/${skill_name}_${timestamp}.md" mkdir -p "$REPORT_DIR" cat > "$report_file" << EOF # 技能评估报告:$skill_name ## 评估摘要 - **评估时间**:$(date '+%Y-%m-%d %H:%M:%S') - **评估方式**:静态分析(选项1 - 轻量) - **技能路径**:$skill_path ## 评估结果 > 报告生成中,需要完善评估模块... ## 下一步 1. 实现各个评估模块 (doc_checker.sh, code_analyzer.sh 等) 2. 完善报告模板 3. 添加评分计算逻辑 EOF ``` ```bash show_summary() { local skill_name="$1" local report_file="$2" echo "" echo -e "${CYAN}🔍 技能评估报告:$skill_name${NC}" echo -e "${BLUE}📊 综合评分:★★★★☆ (4.2/5)${NC}" echo -e "${BLUE}⏱️ 评估用时:$(($SECONDS))秒${NC}" echo -e "${BLUE}📁 技能路径:$skill_path${NC}" echo "" echo -e "${YELLOW}维度得分:${NC}" echo -e " 文档完整性:★★★★☆ (4.0/5)" echo -e " 代码规范性:★★★★★ (4.5/5)" echo -e " 配置友好度:★★★☆☆ (3.5/5)" echo -e " 维护活跃度:★★★★☆ (4.0/5)" echo "" echo -e "${YELLOW}⚠️ 发现问题:3个${NC}" echo -e "${GREEN}✅ 通过检查:21个${NC}" echo -e "${BLUE}📋 详细报告:$report_file${NC}" echo "" } ``` ### Technical Analysis The assessed path and its basename are untrusted filesystem data. They are passed to logging functions that use `echo -e`, which interprets backslash escape sequences. A crafted path con ...[truncated 1733 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This mismatch is materially security-relevant because the skill is presented as a review-only checker yet includes installation/setup actions and filesystem modifications such as chmod, mkdir, cp, and ln -sf into the user's environment. Hidden or under-declared write operations increase the risk of persistence, environment tampering, or accidental modification of trusted skill directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This mismatch is materially security-relevant because the skill is presented as a review-only checker yet includes installation/setup actions and filesystem modifications such as chmod, mkdir, cp, and ln -sf into the user's environment. Hidden or under-declared write operations increase the risk of persistence, environment tampering, or accidental modification of trusted skill directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This mismatch is materially security-relevant because the skill is presented as a review-only checker yet includes installation/setup actions and filesystem modifications such as chmod, mkdir, cp, and ln -sf into the user's environment. Hidden or under-declared write operations increase the risk of persistence, environment tampering, or accidental modification of trusted skill directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch is materially security-relevant because the skill is presented as a review-only checker yet includes installation/setup actions and filesystem modifications such as chmod, mkdir, cp, and ln -sf into the user's environment. Hidden or under-declared write operations increase the risk of persistence, environment tampering, or accidental modification of trusted skill directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch is materially security-relevant because the skill is presented as a review-only checker yet includes installation/setup actions and filesystem modifications such as chmod, mkdir, cp, and ln -sf into the user's environment. Hidden or under-declared write operations increase the risk of persistence, environment tampering, or accidental modification of trusted skill directories.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · evaluators/code_analyzer.sh (reported line 55)May include surrounding context.

sh
# 检查危险权限
    if find "$SKILL_PATH" -type f -name "*.sh" \
       -exec grep -l "chmod.*777\|chmod.*a+rwx" {} \; 2>/dev/null | grep -q .; then
        issues+=("发现过度权限设置 (chmod 777)")
        suggestions+=("使用最小权限原则,如 chmod 755 或 chmod 644")
        security_issues=$((security_issues + 1))
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · evaluators/code_analyzer.sh (reported line 63)May include surrounding context.

sh
# 检查危险操作
    if find "$SKILL_PATH" -type f -name "*.sh" \
       -exec grep -l "rm.*-rf.*\\s*/\\|rm.*-rf.*\\$" {} \; 2>/dev/null | grep -q .; then
        issues+=("发现危险删除操作 (rm -rf /)")
        suggestions+=("避免使用 rm -rf 删除根目录或变量路径")
        security_issues=$((security_issues + 2))  # 严重问题,扣分更多
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · evaluators/code_analyzer.sh (reported line 63)May include surrounding context.

sh
# 检查危险操作
    if find "$SKILL_PATH" -type f -name "*.sh" \
       -exec grep -l "rm.*-rf.*\\s*/\\|rm.*-rf.*\\$" {} \; 2>/dev/null | grep -q .; then
        issues+=("发现危险删除操作 (rm -rf /)")
        suggestions+=("避免使用 rm -rf 删除根目录或变量路径")
        security_issues=$((security_issues + 2))  # 严重问题,扣分更多
    fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises shell-based usage and references executable scripts, but the metadata does not declare any explicit tool scope such as allowed shell access. That ambiguity can cause an agent runtime to grant broader execution capability than users expect, weakening least-privilege controls and making unintended command execution harder to govern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and usage documentation are presented in Chinese, but the file does not indicate that this language choice is optional, user-selected, or required for a region-specific purpose. This can violate language/locale policy when a skill effectively forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger section says the skill applies whenever a user wants to understand a skill's reliability, is choosing between similar skills, wants to check a finished skill, or needs batch assessment. These are broad natural-language situations rather than explicit trigger phrases or bounded activation rules, which can cause unintended invocation overlap with many ordinary requests about skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's user-facing comments, help text, logs, and report content are written in Chinese, and there is no visible option for users to select another language or indication that the skill is intended only for a Chinese-speaking context. That creates a natural-language locale policy concern because the skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated report claims to be an assessment report while its body explicitly says the evaluation modules still need to be completed. This creates a false sense of completion and can be exploited socially or operationally by presenting an unfinished report as evidence that a skill passed review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The summary output presents hard-coded scores, issue counts, and pass counts as if they were computed from the analyzed skill, which can mislead users into trusting a review that never actually happened. In a security or quality assessment context, fabricated results undermine decision-making and can cause unsafe or low-quality skills to be approved based on false assurance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s human-facing comments, labels, and output descriptors are written entirely in Chinese, with no indication that language selection is optional or region-specific. This can violate language/locale policy when a skill or its configuration implicitly fixes one language for users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script embeds natural-language comments and output messages entirely in Chinese, including suggestion text that appears intended for end users. Under the language/locale policy, forcing a specific language without offering choice or documenting a justified region-specific scope is a policy violation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · evaluators/code_analyzer.sh (reported line 55)May include surrounding context.

sh
# 检查危险权限
    if find "$SKILL_PATH" -type f -name "*.sh" \
       -exec grep -l "chmod.*777\|chmod.*a+rwx" {} \; 2>/dev/null | grep -q .; then
        issues+=("发现过度权限设置 (chmod 777)")
        suggestions+=("使用最小权限原则,如 chmod 755 或 chmod 644")
        security_issues=$((security_issues + 1))
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · evaluators/code_analyzer.sh (reported line 56)May include surrounding context.

sh
if find "$SKILL_PATH" -type f -name "*.sh" \
       -exec grep -l "chmod.*777\|chmod.*a+rwx" {} \; 2>/dev/null | grep -q .; then
        issues+=("发现过度权限设置 (chmod 777)")
        suggestions+=("使用最小权限原则,如 chmod 755 或 chmod 644")
        security_issues=$((security_issues + 1))
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · evaluators/code_analyzer.sh (reported line 56)May include surrounding context.

sh
if find "$SKILL_PATH" -type f -name "*.sh" \
       -exec grep -l "chmod.*777\|chmod.*a+rwx" {} \; 2>/dev/null | grep -q .; then
        issues+=("发现过度权限设置 (chmod 777)")
        suggestions+=("使用最小权限原则,如 chmod 755 或 chmod 644")
        security_issues=$((security_issues + 1))
    fi

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script contains natural-language comments and output messages such as "缺少配置文件示例" and "添加环境变量支持,方便容器化部署" entirely in Chinese. Because the file does not indicate that it is intended only for Chinese-speaking users or provide any language/locale opt-in, it forces a specific language and can violate locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script emits user-facing comments, issue messages, and suggestions in Chinese only, including the JSON error output. That imposes a specific language/locale on users without opt-in or documented justification, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell skill contains natural-language comments, issue strings, and suggestion strings in Chinese throughout, with no indication that the skill is intentionally region-specific or that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This YAML file contains user-facing natural-language content exclusively in Chinese, including setup comments and report template text. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy violation, and no alternative language or locale constraint is documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all user-facing content in a single forced language, which can violate a language/locale policy when no user opt-in or alternative is offered. Nothing in the file indicates that the skill is region-specific or that Chinese-only output is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script presents all user-facing messages in Chinese, including installation status, errors, and usage instructions. That creates a language/locale policy concern because the skill forces a specific language without user opt-in or any indication that it is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.