Back to skill

Security audit

editor-classify-and-parse

Security checks for vulnerabilities and agentic risk

Overview

This skill only classifies and summarizes script/story input and does not request risky system access.

Reasonable to install if you want a Chinese-language script classification helper. Consider asking the publisher to add an explicit rule to preserve the user's preferred response language, but no high-impact access or hidden behavior was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is explicitly authored in Chinese and all operational instructions are presented only in that language, which can implicitly force interactions or outputs in a specific language without confirming user preference. This is mainly a policy/compliance issue rather than a direct security exploit, but it can cause incorrect handling of user input, degraded reliability, or bypass of expected user-language controls in multilingual environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.