Back to skill

Security audit

素材库管理

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple in-memory material library with no evidence of hidden access, persistence, external network use, or destructive behavior.

Review this as an incomplete, Chinese-language material-library prototype: it can search, version, and archive only records currently held in memory, while upload/storage is not functional through the command interface. Pinning dev dependency versions would improve reproducibility, but I found no hidden persistence, credential access, network calls, or destructive actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents actions that store files and update existing material versions, which can affect user data. Under the markdown-specific warning rule, the description should disclose that these actions create or modify stored content, but no such warning or caution is present in the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's user-facing command descriptions, argument help text, error messages, and success messages are written only in Chinese. This imposes a specific language on users without any opt-in, alternative locale, or justification that the skill is intended solely for a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a material library that provides storage, retrieval, and version management. However, the exposed upload subcommand is documented as "上传素材" yet its execute handler always returns success: false with an error saying upload requires extra integration, so the advertised storage capability is not actually implemented through the skill interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and primary documentation text are written in Chinese, but there is no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill imposes a language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description is presented only in Chinese, which can indicate a language/locale constraint without user opt-in. For a general-purpose package manifest, there is no accompanying note that the skill is intended only for Chinese-speaking users or a specific regional context.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"license": "MIT",
  "dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Static analysis

No suspicious patterns detected.