Back to skill

Security audit

Work Mode Switch

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only mode-switching skill with some ambiguous wording, but no hidden code, persistence, credential handling, or exfiltration behavior was found.

Before installing, understand that this skill can influence how an agent interprets casual phrases as work modes. Prefer explicit commands such as 'switch to review mode', and confirm before allowing file creation, cleanup, memory updates, or system-maintenance actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

多个模式的触发词覆盖日常高频表达,如“写一个”“检查”“完成”“搞定”等,容易在普通对话中被误判为模式切换指令。对具备工具、文件或执行能力的代理而言,误触发会直接改变行为约束,导致本应先确认的任务被提前执行。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

默认“自由模式”配合“根据上下文判断任务类型”的表述,使代理在缺少明确激活边界时拥有较大自主裁量空间。安全上这会把模糊请求升级为实际操作指令,尤其当“自由模式”又被描述为“边说边干”时,更容易绕过确认步骤。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

把“整理一下”作为自检模式触发词尤其危险,因为该短语常被用户用于文件整理、内容重组、目录清理等实际操作请求。即使正文写明“自检模式”不执行文件操作,触发词本身仍会与执行型任务混淆,造成代理错误进入检查/整理语境,或被实现者误扩展为自动整理动作。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

隐式切换规则允许在“模糊任务”下由代理自动判断模式,但未给出触发门槛、优先级、冲突解决或必须澄清的条件。这样的设计会使代理在含糊表达下自行选择更积极的执行路径,扩大误执行、越权操作或错误使用工具的概率。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly states that in the absence of a clear instruction, the skill will auto-detect and default into a working mode. For an agent skill that changes behavior and can later influence execution posture, broad implicit activation increases the chance of mode switching without informed user consent, causing unintended actions or altered safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The self-check checklist includes operations touching memory files, HEARTBEAT.md synchronization, file integrity checks, temporary file cleanup, and TODO updates, but the README does not warn about scope, permissions, or possible side effects. Even documentation-level endorsement of autonomous maintenance behavior can normalize file modification or deletion without clear boundaries, creating risk of data loss or unintended system changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

“有空吗”“先聊聊”等短语在自然会话中极常见,但被映射到具体模式后会影响代理后续行为路径。虽然单独看危害不如直接执行类触发词高,但它会制造模式歧义,进而让代理在闲聊、规划和任务处理之间切换错误。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

速查表把“自检”写成“自动执行”、把“自学”写成“独立推进”,与前文“仅提供建议/清单、不自动执行”的限制相冲突。对按速查表快速实现或调用此技能的代理来说,这会弱化人工确认边界,增加未经明确授权就执行检查、整理或持续推进任务的风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

该技能文档通篇以中文规定交互命令、示例和模式说明,但未说明是否支持其他语言触发、是否允许依据用户偏好切换语言。对于组织语言/地区策略而言,这可能构成默认强制单一语言而无用户选择。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description explicitly presents the skill as a Chinese-language guide ("智能体工作模式切换指南") with no indication that users can choose another language or that the locale restriction is intentional for a region-specific use case. This is a natural-language policy concern because it imposes a language context without documented opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.