Back to skill

Security audit

资源交付分发

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a straightforward ad-material packaging and distribution helper, with no hidden execution, persistence, credential access, or real network upload code in the inspected artifacts.

Install this if you are comfortable with a Chinese-language workflow for ad-material packaging and distribution. Before using any future real platform-upload version, verify which assets, platform configuration, and account credentials are sent to third-party services and require explicit confirmation before distribution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly supports distributing materials to external platforms and accepts arbitrary platform configuration, but it does not warn users that content and configuration data may be transmitted to third-party services. This can lead to unintended disclosure of creative assets, account identifiers, API settings, or other sensitive metadata during normal use, especially in multi-tenant or regulated environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The registered command uses Chinese-only descriptions, help text, and returned user-facing messages throughout the command definitions. This imposes a specific language on users without any opt-in or documented locale constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description is written entirely in Chinese, which indicates a language-specific user-facing description without any indication that users can choose another language. The policy for this category requires flagging language or locale constraints unless they are optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and changelog are written in Chinese, and the rest of the document mixes English headings with Chinese operational content. This can functionally force a specific language for users without any opt-in or documented justification for a locale-specific skill.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"license": "MIT",
  "dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Static analysis

No suspicious patterns detected.