Back to skill

Security audit

无障碍标签审查与自动修复

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not malicious, but it can automatically change project code over a broad default scope without requiring clear confirmation.

Install only if you are comfortable with an agent editing accessibility-related code. Use explicit target paths, ask for report-only or dry-run behavior first, and review diffs before accepting changes, especially in large repositories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that the skill will automatically fix accessibility issues but does not clearly warn that project files may be changed. In a tool that can perform edits, lack of upfront disclosure can lead to unexpected modifications, especially if the skill is triggered broadly or used in a large codebase.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad, generic accessibility terms that overlap with ordinary user requests, so the skill may activate when the user did not explicitly intend to invoke it. Because the skill can scan and automatically modify files, unintended invocation increases the chance of surprise code changes or noisy edits in unrelated contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

整个技能说明以中文固定呈现,且未声明可根据用户偏好切换语言或接受其他语言输入/输出。按规则,强制特定语言但未提供选择或明确、合理的地区性约束,属于自然语言策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L011-L012 使用“无障碍改进”“兼容性问题”等宽泛表述作为触发条件,这些短语在日常开发讨论中覆盖面很广,且未限定必须与 React/TSX 审查或自动修复相关。文档也没有提供排除条件或负例,导致技能何时应激活、何时不应激活不够明确。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly states it will scan the current directory or specified files and automatically apply fixes, but it does not require an explicit confirmation or warn about the risk of bulk modification. In an agentic environment, this can lead to unintended mass edits, corruption of unrelated files, or unsafe changes being applied beyond the user's intended scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage text prominently states that the skill will automatically scan and repair code, and later run lint checks, but does not provide an upfront warning in the behavior description that files may be modified or commands may be executed. In an agent setting, this can create unsafe expectations and cause users to invoke the skill without realizing it may perform write actions or environment-dependent verification steps.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill can be triggered by very broad natural-language phrases such as general accessibility review requests, which increases the chance of accidental invocation in normal conversations. Because this skill is described as automatically scanning, modifying files, and later running checks, a false trigger could lead to unintended code changes or workflow disruption without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The tagline and description are entirely in Chinese, and the file provides no indication that language is selectable or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains natural-language content exclusively in Chinese, and there is no indication that users may choose another language or that the file is intentionally region-specific. Under the policy rule for language/locale constraints, forcing a single language without opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Nearly all user-facing instructions and invocation guidance in the README are presented only in Chinese. Because the file does not offer an alternative language or indicate that Chinese is an intentional locale-specific constraint, it may violate language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

文件标题、正文、命令示例及生成内容示例均固定为中文,没有说明用户可选择其他语言,也未将该限制解释为特定地区或组织要求。这可能构成语言/locale 约束未获用户选择的自然语言策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file’s instructional content, examples, and report template are all presented only in Chinese, with no indication that the user can opt into another language or that the skill is intentionally region-specific. Under the policy, forcing a specific language without user choice or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions, examples, and guidance exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in or a documented locale-specific justification is a reportable issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.