Back to skill

Security audit

Popeye Coding

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language coding helper with broad triggers but no executable code, persistence, credential access, or hidden data handling.

Install this if you want a Chinese coding assistant for generating, debugging, and reviewing code. Be aware that generic phrases like “写代码”, “调试”, or “代码审查” may invoke it during normal coding conversations, and avoid pasting secrets or proprietary code unless you are comfortable sharing that content with the assistant runtime.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases described in the skill metadata are broad coding-related terms that can easily appear in ordinary user conversation. This can cause unintentional skill activation, routing coding requests into this skill when the user did not explicitly intend to invoke it, which may lead to incorrect task handling or reduced user control.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation table lists generic phrases like '写代码', '调试', and '代码审查' without defining when they should or should not activate the skill. In a conversational assistant, such broad matching increases the risk of accidental invocation and ambiguous dispatch, especially because these are common task descriptions rather than uniquely identifying commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title, trigger phrases, prompt template, and output format all assume Chinese-language interaction, and there is no indication that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file defines activation phrases, so SQP-1 applies. The trigger 调试 is very generic and could match many ordinary requests about troubleshooting or debugging without clearly delimiting when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very generic ('写代码' / '帮我写代码') and can be activated by many ordinary user requests, causing this skill to override or intercept broader conversations than intended. In an agent system with multiple skills, overly broad activation can lead to incorrect routing, unexpected prompt injection surface expansion, or unintended privileged behavior if this skill is invoked in contexts where code generation was not explicitly desired.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L001 标题及全文均以中文固定呈现,且未说明用户可选择其他语言输出,也没有给出地域或合规上的必要性说明。根据 SQP-3,未经用户选择而强制单一语言属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase “帮我审查代码” is broad and overlaps with normal conversational requests, so the skill may activate when the user did not explicitly intend to invoke this specific review workflow. In an agent setting, ambiguous activation can cause unintended prompt injection of the skill’s formatting and behavior, reducing user control and potentially interfering with safer or more appropriate handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The phrase is natural and broad enough to overlap with everyday speech, and the file does not provide exclusion conditions or clear boundaries for invocation. Without context requirements, it may activate on vague requests that are not intended for this specific debugging workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.