Back to skill

Security audit

Junqi Dark Layout

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused Junqi layout helper that validates and renders game boards locally, with no evidence of hidden access, persistence, network use, or destructive behavior.

Install this if you want a Chinese-language Junqi layout generator with local validation and image rendering. Be aware that it enforces some opinionated strategy constraints, so it may reject layouts that another Junqi player might consider acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains multiple hard-coded Chinese strings used in rendered output and defaults, such as the banner text and cell labels. Because the skill does not offer a language or locale choice, it appears to enforce a specific language in a way that can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section goes beyond strict validation and embeds subjective heuristics, including the fixed HQ composition rule and the 'important pieces not trapped' logic. In a skill whose description promises strict hard-rule validation, mixing policy and heuristic logic can silently bias outputs, reject legal user input, and undermine any security or workflow decisions that rely on validator results as objective truth.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The validator is presented as performing hard-rule legality checks, but this block enforces a specific strategy choice: the two HQ cells must be exactly 军旗 and 排长. That creates an integrity issue because valid layouts can be rejected or manipulated according to an undocumented preference, which is especially risky when downstream components trust the validator as an authoritative legality gate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.