Back to skill

Security audit

云指建站助手

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed SaaS website-building skill that can make persistent changes to a user-specified site, but its access and write behavior are purpose-aligned and gated by user-provided credentials and confirmations.

Install only if you intend to let the agent administer a specific SaaS website through its MCP endpoint. Provide only a site-specific Bearer token, review each proposed write/delete/batch import/SQLite operation before confirming, and add proper privacy notices when generated forms collect phone numbers, email addresses, ID data, regions, or file uploads.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invocation guidance includes broad, everyday phrases plus catch-all wording such as tasks involving building or managing websites, which can cause the skill to activate outside narrowly intended situations. In this skill, over-activation is risky because the skill is authorized to query and modify live website content through MCP tools, increasing the chance of unintended writes, data changes, or destructive operations being proposed in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The rule states that when creating non-Chinese webpages based on example code, the Chinese in the examples must be translated into the target language. This imposes a language-specific default behavior tied to Chinese source material rather than explicitly offering the user a language or locale choice at that point.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly exposes a template-level function, FnSqliteExecute, that can perform arbitrary SQLite write operations such as INSERT, UPDATE, DELETE, and CREATE directly from front-end template logic. In the context of this skill, which supports automated website creation/modification and can be used end-to-end by other agents, this materially increases the risk of unintended or attacker-influenced data modification, destructive writes, and persistence abuse if templates incorporate untrusted input or are generated automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains a full form template that collects potentially sensitive data such as phone numbers, email addresses, ID card numbers, region data, and uploaded files, then sends them to backend endpoints with fetch(). The surrounding markdown notes discuss implementation details only and do not warn users that the example performs network transmission of submitted data and files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown description explains that uploaded files are saved first and later submitted by path, but it does not warn users that files, enquiry contents, phone numbers, email addresses, and region data are transmitted to backend endpoints. Under the markdown-file criteria, skills should disclose behaviors that may affect user data or privacy, and this description omits such a warning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file title and all authoring guidance are presented exclusively in Chinese, effectively imposing a single language for skill usage or outputs. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Most of the template and instructions are in Chinese, but the international-region section hardcodes English strings such as 'select country' and 'please select province/state'. This imposes locale-specific output without any documented user opt-in or configurable language selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

这是一个 markdown 文件,适用自然语言策略检查。标题和全文说明均固定为中文,没有提供多语言选项、英文别名,或说明该技能仅面向中文用户/中文站点场景,可能构成未经用户选择的语言/区域限制。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The form collects a phone number and SMS verification code but does not provide any user-facing notice about why the data is being collected, how it will be used, or that it will be transmitted to backend endpoints. This is primarily a privacy/compliance weakness rather than a direct exploit path, but in a website-builder skill that can be reused across many customer sites, it increases the risk of undisclosed personal-data collection at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Most of the skill is written in Chinese, but the international region field hard-codes English prompts such as "select country" and "please select province/state". This imposes a specific language choice in part of the user experience without opt-in or documented justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.