Back to skill

Security audit

Docs Improver

Security checks for vulnerabilities and agentic risk

Overview

This documentation helper is mostly purpose-aligned, but its default generation workflow can overwrite existing project documentation without a clear warning or confirmation.

Review this skill before installing if you plan to run it on an important repository. Use a clean git worktree or a separate output directory, and avoid the combined or generation modes unless you are prepared for README.md and docs files to be replaced.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.py:348
Finding

Default generation workflow unconditionally overwrites existing documentation

Content
View full analysis
/README.md`, regardless of whether the file already exists. `generate_readme()` opens the selected path using mode `w`. In Python, this mode immediately truncates an existing regular file before writing the generated content. There is no existence check, backup, preview, interactive confirmation, exclusive-create mode, or explicit overwrite option. This behavior exceeds the minimum write privileges needed to generate missing documentation. The declared functionality can be implemented by creating absent documents while preserving existing files by ...[truncated 2417 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

声明与代码部分匹配:代码确实会分析文档质量并生成改进建议,也支持多种常见文档格式。 但存在重要能力不一致。首先,声明强调可自动生成缺失文档,而代码只是在没有文档时报告问题,并不会生成 README 或 API 文档。其次,声明称会检查文档与代码一致性,但代码没有读取或分析源码内容,也没有做任何交叉验证。再次,虽然声明包含“准确性”评估,但实现中准确性被硬编码为 70,缺乏实际检测逻辑。因此该技能描述显著高于代码实际能力,属于描述与行为不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个覆盖文档质量评估、缺失文档生成、一致性检查和改进规划的综合型文档工具;但提供的代码只实现了非常有限的静态一致性检查。它会遍历 Markdown 和 Python 文件,提取 API 路由、检查文档中的函数示例是否对应到 Python def 定义、检查本地相对链接是否存在,并输出问题报告。这确实部分符合“文档与代码一致性检查”,但并不支持声明中的大部分核心能力,尤其是自动生成 README/API 文档、全面评估文档质量维度、面向所有编程语言的支持,以及更系统化的改进规划。因此描述明显夸大了实际能力,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad documentation audit and improvement tool, with capabilities for quality assessment, consistency checking, suggestion generation, and support for all languages. The supplied code only implements document generation: README, API.md, and ARCHITECTURE.md. Its analysis is shallow and narrowly scoped—e.g., API endpoint extraction only scans Python files for Flask/FastAPI-style decorators, and architecture detection is based on directory names. There is no logic to score or assess existing documentation quality, compare docs against code for consistency, generate improvement recommendations, or perform release-readiness/document-audit workflows. While generating missing docs is aligned with part of the description, the overall declared purpose materially overstates the implemented behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a broad, professional documentation auditing and generation tool. However, the code only performs lightweight structural checks: whether README.md exists, whether it contains certain keywords/code fences, whether examples/ and docs/ directories exist, and whether a few named files are present. It then produces recommendations and can export them as a markdown checklist. There is no implementation for automatic documentation generation, no code parsing or doc/code consistency analysis, and no substantive assessment of accuracy or clarity. The primary purpose partially overlaps with 'providing improvement suggestions,' but the overall declared scope is materially broader than the actual behavior, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises commands that read from and write to project paths, but the manifest does not declare any explicit tool scope or permissions boundary. This is dangerous because an agent or reviewer cannot easily tell that the skill may modify repository files, increasing the risk of unexpected writes, overwrite of documentation, or broader file-system access than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation does not clearly warn that it can generate and write documentation files into project or output directories. This is dangerous because users may invoke it expecting read-only analysis, leading to unintended repository changes, file overwrites, or pollution of working trees in sensitive environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The visible natural-language description and headings are entirely in Chinese, while the skill claims broad applicability across all programming languages. For a general-purpose skill, forcing a specific language without opt-in can violate language/locale policy unless the restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes broader capabilities including automatic generation of missing documentation such as README/API docs and checking documentation against code for consistency. In this implementation, the analyzer only scans existing .md/.rst/.txt/.adoc files, computes simple content-based scores, and writes a markdown report; it never inspects source code or generates missing documentation files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code performs a file write operation when exporting the generated report. Although the behavior is implicit in the --output argument and function name, there is no explicit warning in the docstring or surrounding comments that an existing file at the target path may be created or overwritten.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes broader documentation-improvement behavior including automatic generation of missing documentation, while this script's implemented behavior is limited to scanning markdown/Python files and optionally writing a report. That makes the file's actual operations narrower than the claimed capability, indicating a description-behavior mismatch at the skill level for this component.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This code performs a file write to output_path, which can overwrite or create files on disk. Although the method docstring says 'Export issues to Markdown', there is no explicit warning, confirmation, or overwrite notice near the write operation or CLI argument that alerts users to this filesystem impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.