Back to skill

Security audit

Aloudata CAN SKILLS - anomaly-detection

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent metric anomaly-detection skill that analyzes queried business metrics and does not include hidden execution, persistence, or destructive behavior.

Before installing, users should understand that this skill may query business metric data through the metric-query workflow and may be triggered by broad Chinese health-check wording. Its behavior is disclosed and analysis-focused, but teams may want to tighten trigger phrases or clarify the Gateway API wording for cleaner routing and governance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger conditions are extremely broad and include common phrases like '帮我看看有没有问题' and '有没有风险,' which can cause unintended invocation in unrelated contexts. Overbroad routing can expose data to the wrong skill, create incorrect autonomous actions, and bypass least-privilege expectations by initiating anomaly-analysis workflows when the user did not clearly request them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language description and operating instructions are written to require use of this skill under Chinese-language trigger conditions, with no indication that users may choose another language or locale. Because the skill does not offer language choice or document a justified region-specific constraint, it appears to enforce a specific language by default.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest explicitly states that all data queries must be delegated to metric-query and that this skill does not directly call the Gateway API. Later documentation says the skill calls metric-query's query capability 'through Gateway API', which contradicts the earlier prohibition and creates ambiguity about the actual integration boundary.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Earlier sections repeatedly define the skill's intent boundary as delegating all querying to metric-query without directly calling Gateway API. Line L459 instead states that this skill calls metric-query's querying capability 'through Gateway API', which is an active contradiction in the written intent and operating model.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.