Back to skill

Security audit

skill-subtraction

Security checks for vulnerabilities and agentic risk

Overview

This skill audits installed AI skills and can recommend cleanup, with scan behavior disclosed and destructive actions gated on explicit confirmation.

Install only if you are comfortable letting it inventory your agent skill directories and surface local skill metadata in a report. Review any archive or uninstall plan carefully and approve cleanup only for skills you really want changed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to inspect local skill directories, read SKILL.md files, and optionally scan archive/workspace paths, but it declares no permissions or capability boundaries. That mismatch can cause users or platforms to underestimate the file-system access involved, increasing the risk of unintended disclosure of local metadata or execution in contexts where such access should require explicit approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The public description frames the skill as a recommendation/reporting tool, but the instructions authorize broader collection of local filesystem metadata, archive inventory details, workspace scanning, and integrity/error reporting. This description-behavior gap is dangerous because users may consent to a simple skill audit without realizing the skill can enumerate additional paths and emit detailed local state information that could expose sensitive project or environment metadata.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises broad natural-language triggers like 'Clean up my skills' and 'Which skills should I keep or delete?', which are common phrases that could appear in ordinary conversation and cause the skill to auto-trigger unexpectedly. Because this skill scans installed skills across platforms and workspace/project-level locations, accidental invocation can lead to unintended metadata enumeration and recommendations in contexts where the user did not explicitly intend a cross-skill audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises very broad, natural-language trigger phrases such as 'Check what skills I have installed' and 'Audit my skills'. In agent platforms that auto-trigger skills from conversational intent, overly generic phrases can cause unintended activation and start enumeration or cleanup workflows when the user did not intend to invoke this specific skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The trigger examples are broad natural-language phrases such as asking to check installed skills or clean up skills, which can overlap with ordinary conversation and cause the skill to activate unexpectedly. In this skill's context, unintended activation is meaningful because the workflow includes scanning installed skills across platforms and potentially proceeding toward archive/uninstall recommendations, increasing the chance of unnecessary local enumeration or confusing cleanup actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README describes scanning all installed skills, archived skills, installation sources, and metadata, but does not clearly warn users about the scope of local data being enumerated or how that information may appear in reports. While this is not direct data exfiltration by itself, insufficient disclosure can lead users to authorize a scan without understanding that cross-platform inventory and archive details will be collected and surfaced.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger phrases are broad enough to match common requests like listing skills, cleanup, decluttering, or deciding what to keep/delete. Over-broad activation can cause this skill to run in situations where the user did not intend a filesystem scan or recommendation workflow, leading to unnecessary local enumeration and increased chance of accidental destructive follow-up actions.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
92% confidence
Finding

The skill is designed to enumerate installed skills across one or many agent platforms, including project-level skill directories. This creates a genuine information-exposure risk because skill names, paths, sources, and metadata can reveal tooling, projects, internal workflows, or security-sensitive agent capabilities to the running agent or any downstream component handling the report.

Content

Scanner excerpt · README_en.md (reported line 19)May include surrounding context.

md
## Features

- **Auto-scan**: One-click scan of all installed skills under the current Agent platform. The script auto-detects its host platform via its own path — placed under `~/.workbuddy/skills/` it scans WorkBuddy, under `~/.codex/skills/` it scans Codex, and so on; also scans the current workspace's `.workbuddy/skills/` for project-level skills
- **Bilingual output**: Supports both Chinese and English reports via `--lang zh` (default) or `--lang en` flag; stderr messages, issue descriptions, and audit report templates are fully localized
- **Multi-platform**: Not just WorkBuddy — compatible with Codex, Claude Code, Cursor, Cline, Continue, LobsterAI, and any AI assistant platform that follows the `~/.<agent>/skills/` directory convention; use `--all` to scan all installed platforms at once
- **Categorized evaluation**: Classifies skills into Tool / Business / News / Productivity types, scoring across 6 metrics (usage frequency, necessity, current relevance, enabled status, maintenance status, unique value)

Static analysis

No suspicious patterns detected.