Back to skill

Security audit

my-test-skill

Security checks for vulnerabilities and agentic risk

Overview

This security-scanner skill is mostly coherent, but it sends matched code evidence to a third-party cloud service by default and its own documentation does not reliably prevent secrets from being included.

Install only if you are comfortable with source-derived evidence being sent to NetEase Yidun by default. For private repositories, proprietary packages, or code that may contain hardcoded secrets, set YIDUN_SKILL_SEC_CLOUD=false before use or avoid the skill until it offers opt-in cloud submission, payload review, stronger redaction, and SHA-256 based fingerprints.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:226
Finding

Default cloud evidence upload can disclose secrets contained in matched source lines

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 226-246 and 304-346
Vulnerability Type: Uncontrolled disclosure of sensitive source data to a third-party endpoint
Risk Level: High

Vulnerable Code Snippet

text
### 3.1 What Gets Sent

The fingerprint manifest, behavior tags, and **extracted evidence artifacts** are uploaded. Evidence includes the specific URLs, shell commands, and credential access paths that triggered each tag — enabling the cloud to perform real content-level threat analysis.

**Evidence redaction rules** — before upload, the scanner applies the following sanitization:
- Environment variable **values** are replaced with `[REDACTED]` (only the variable name is sent)
- File content from sensitive paths (`~/.ssh`, `~/.aws`, `~/.env`) is never included — only the **path** and **access pattern** are sent
- The `context` field is truncated to the single matched line; multi-line context is not collected
- Full source code is NOT sent — only the lines that triggered a detection tag
text
| Sub-field | Description |
|-----------|-------------|
| `tag` | The behavior tag that was triggered |
| `value` | Raw extracted value (URL / command / path) |
| `file` | Source file path where the pattern was found |
| `line` | Line number of the match |
| `context` | Full content of the matched line |

Technical Analysis

Cloud analysis is enabled by default and sends extracted evidence to https://as.dun.163.com/v1/agent-sec/skill/check. The evidence format permits both a raw extracted value and the complete content of the matched source line.

The documented redaction policy only guarantees removal of environment-variable values and file content read from a limited set of sensitive paths. It does not cover other common secret representations, including:

  • Hardcoded API keys, passwords, private keys, or bearer tokens
  • Authorization headers and cookies embedded in s ...[truncated 2325 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make cloud evidence upload explicitly opt-in rather than enabled by default.
  2. Display the exact outbound payload and destination and require informed user approval before transmission.
  3. Do not upload complete matched lines. Extract only the minimum structured feature needed for classification.
  4. Replace denylist-based redaction with allowlist-based serialization so unknown fields and raw context are excluded by default.
  5. Redact authorization headers, cookies, URL credentials, sensitive query parameters, private-key blocks, command arguments, and known credential formats.
  6. Detect and redact high-entropy strings even when their variable names do not contain terms such as TOKEN or SECRET.
  7. Canonicalize and validate evidence after redaction, then run a second secret-scanning pass over the final serialized request.
  8. Prefer local classification for sensitive-path and credential-access findings; send only tag names and non-reversible identifiers.
  9. Document remote retention, logging, access-control, deletion, and cache policies.
  10. Add tests proving that secrets embedded in URLs, headers, commands, and matched source lines never appear in outbound requests.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:125
Finding

Collision-broken MD5 is used as the package security fingerprint

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 125-143
Vulnerability Type: Use of a cryptographically broken hash for security identity and cache lookup
Risk Level: Medium

Vulnerable Code Snippet

bash
# Example: compute file hashes
find /tmp/pkg -type f -exec openssl dgst -md5 {} \;

# Example: composite fingerprint
find /tmp/pkg -type f -exec openssl dgst -md5 {} \; | sort | openssl dgst -md5

Technical Analysis

The Skill instructs the Agent to compute an MD5 digest for every file and another MD5 digest over the sorted per-file output. This composite value is described as a package fingerprint used for cache lookups and audit trails.

MD5 is collision-broken and is not suitable for adversarial content identification. An attacker capable of constructing colliding inputs can cause distinct data to share the same digest. Applying MD5 a second time to a manifest of MD5 values does not restore collision resistance.

The construction also relies on textual command output rather than a clearly specified canonical manifest. The documentation does not define robust encoding and binding of normalized paths, file types, permissions, sizes, or metadata. This can create additional ambiguity across platforms or scanner implementations.

Attack Path

  1. An attacker prepares package content designed to collide under the MD5-based fingerprint process.
  2. A benign package or variant is scanned first and receives a trusted or cached-safe cloud verdict.
  3. The attacker distributes a different package whose relevant MD5 fingerprint is identical.
  4. The scanner submits the ambiguous fingerprint for a cache lookup.
  5. If the remote service treats the fingerprint as a unique package identity, it may return the prior safe result without sufficiently analyzing the different content.
  6. The malicious package benefits from an incorrect trust association or misleading audit record.

Practical exploitat ...[truncated 583 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace MD5 with SHA-256 or SHA-512 for every file and for the composite package fingerprint.
  2. Define a deterministic binary or canonical JSON manifest rather than hashing tool-specific textual output.
  3. Bind each digest to a normalized relative path, file size, file type, executable status, and other security-relevant metadata.
  4. Reject duplicate, absolute, parent-traversal, or normalization-conflicting paths before fingerprinting.
  5. Include an explicit fingerprint-scheme version and algorithm identifier in cache keys.
  6. Require the cloud service to verify the complete manifest rather than trusting only one composite digest.
  7. Invalidate existing MD5-only cache entries or require a fresh scan when migrating to the new fingerprint format.
  8. Use signed registry manifests where available and verify signatures independently of the content hash.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (31)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README.md (reported line 3)May include surrounding context.

md
# yidun-skill-sec ⚡

> Hybrid local-cloud security scanner for AI agent skills. Scans fast, scores precisely, fails safely.

---

## Overview

`yidun-skill-sec` is a security vetting skill that analyzes third-party code packages before installation. It combines static behavioral analysis with cloud threat intelligence to produce a quantified safety score, catching malware, data exfiltration, privilege abuse, prompt injection, and obfuscation — before anything runs.

Built by the **Yidun Security Team** for the [ClawHub](https://clawhub.com) ecosystem.

## Security Disclosure

This skill uploads **non-sensitive metadata** (file hashes, behavior tag names

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
# yidun-skill-sec ⚡

> Hybrid local-cloud security scanner for AI agent skills. Scans fast, scores precisely, fails safely.

---

## Overview

`yidun-skill-sec` is a security vetting skill that analyzes third-party code packages before installation. It combines static behavioral analysis with cloud threat intelligence to produce a quantified safety score, catching malware, data exfiltration, privilege abuse, prompt injection, and obfuscation — before anything runs.

Built by the **Yidun Security Team** for the [ClawHub](https://clawhub.com) ecosystem.

## Security Disclosure

This skill uploads **non-sensitive metadata** (file hashes, behavior tag names

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

md
| `COOKIE_SESSION` | Reads browser cookies or session tokens |
| `BYPASS_SAFETY` | `--no-verify`, `--force`, `--skip-ssl`, `GIT_SSL_NO_VERIFY` |
| `DESTRUCTIVE_OP` | `rm -rf`, `DROP TABLE`, `git reset --hard`, `dd if=` |
| `PROMPT_INJECT` | Natural language directives targeting the AI agent, attempting to override its rules, bypass constraints, or assume an unrestricted persona |

> **Hard rules**: `CRED_HARVEST` or `PRIV_ESCALATION` → floor to SEVERE. Both present → force CRITICAL.

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
| `COOKIE_SESSION` | Reads browser cookies or session tokens |
| `BYPASS_SAFETY` | `--no-verify`, `--force`, `--skip-ssl`, `GIT_SSL_NO_VERIFY` |
| `DESTRUCTIVE_OP` | `rm -rf`, `DROP TABLE`, `git reset --hard`, `dd if=` |
| `PROMPT_INJECT` | Natural language directives targeting the AI agent, attempting to override its rules, bypass constraints, or assume an unrestricted persona |

> **Hard rules**: `CRED_HARVEST` or `PRIV_ESCALATION` → floor to SEVERE. Both present → force CRITICAL.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

md
| `EXEC_DYNAMIC` | `eval()`、`exec()`、动态代码执行 |
| `ENCODE_DECODE` | Base64/Hex 编解码链(潜在混淆) |
| `CRED_HARVEST` | 从环境变量或文件读取 API Key、Token、密码 |
| `PRIV_ESCALATION` | `sudo`、`chmod 777`、`setuid` 等提权操作 |
| `OBFUSCATED` | 混淆/压缩代码、不可读变量名 |
| `AGENT_MEMORY` | 访问 Agent 身份/记忆文件 |
| `PKG_INSTALL` | 安装未声明的系统依赖包 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.zh-CN.md (reported line 79)May include surrounding context.

md
| `EXEC_DYNAMIC` | `eval()`、`exec()`、动态代码执行 |
| `ENCODE_DECODE` | Base64/Hex 编解码链(潜在混淆) |
| `CRED_HARVEST` | 从环境变量或文件读取 API Key、Token、密码 |
| `PRIV_ESCALATION` | `sudo`、`chmod 777`、`setuid` 等提权操作 |
| `OBFUSCATED` | 混淆/压缩代码、不可读变量名 |
| `AGENT_MEMORY` | 访问 Agent 身份/记忆文件 |
| `PKG_INSTALL` | 安装未声明的系统依赖包 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
| `EXEC_DYNAMIC` | `eval()`、`exec()`、动态代码执行 |
| `ENCODE_DECODE` | Base64/Hex 编解码链(潜在混淆) |
| `CRED_HARVEST` | 从环境变量或文件读取 API Key、Token、密码 |
| `PRIV_ESCALATION` | `sudo`、`chmod 777`、`setuid` 等提权操作 |
| `OBFUSCATED` | 混淆/压缩代码、不可读变量名 |
| `AGENT_MEMORY` | 访问 Agent 身份/记忆文件 |
| `PKG_INSTALL` | 安装未声明的系统依赖包 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

md
| `PKG_INSTALL` | 安装未声明的系统依赖包 |
| `COOKIE_SESSION` | 读取浏览器 Cookie 或会话 Token |
| `BYPASS_SAFETY` | `--no-verify`、`--force`、`--skip-ssl`、`GIT_SSL_NO_VERIFY` |
| `DESTRUCTIVE_OP` | `rm -rf`、`DROP TABLE`、`git reset --hard`、`dd if=` |
| `PROMPT_INJECT` | 包含针对 AI Agent 的自然语言指令,试图覆盖其规则、绕过约束或伪装为无限制人格 |

> **硬性规则**:命中 `CRED_HARVEST` 或 `PRIV_ESCALATION` → 强制 SEVERE;两者同时命中 → 强制 CRITICAL。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.zh-CN.md (reported line 85)May include surrounding context.

md
| `PKG_INSTALL` | 安装未声明的系统依赖包 |
| `COOKIE_SESSION` | 读取浏览器 Cookie 或会话 Token |
| `BYPASS_SAFETY` | `--no-verify`、`--force`、`--skip-ssl`、`GIT_SSL_NO_VERIFY` |
| `DESTRUCTIVE_OP` | `rm -rf`、`DROP TABLE`、`git reset --hard`、`dd if=` |
| `PROMPT_INJECT` | 包含针对 AI Agent 的自然语言指令,试图覆盖其规则、绕过约束或伪装为无限制人格 |

> **硬性规则**:命中 `CRED_HARVEST` 或 `PRIV_ESCALATION` → 强制 SEVERE;两者同时命中 → 强制 CRITICAL。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
| `PKG_INSTALL` | 安装未声明的系统依赖包 |
| `COOKIE_SESSION` | 读取浏览器 Cookie 或会话 Token |
| `BYPASS_SAFETY` | `--no-verify`、`--force`、`--skip-ssl`、`GIT_SSL_NO_VERIFY` |
| `DESTRUCTIVE_OP` | `rm -rf`、`DROP TABLE`、`git reset --hard`、`dd if=` |
| `PROMPT_INJECT` | 包含针对 AI Agent 的自然语言指令,试图覆盖其规则、绕过约束或伪装为无限制人格 |

> **硬性规则**:命中 `CRED_HARVEST` 或 `PRIV_ESCALATION` → 强制 SEVERE;两者同时命中 → 强制 CRITICAL。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
| `AGENT_MEMORY` | Accesses agent memory files (identity, preferences, context) | +25 |
| `PKG_INSTALL` | Installs unlisted system packages or dependencies | +20 |
| `COOKIE_SESSION` | Reads browser cookies, localStorage, session tokens | +25 |
| `BYPASS_SAFETY` | Uses flags that skip security checks: `--no-verify`, `--force`, `--allow-root`, `--skip-ssl` | +20 |
| `DESTRUCTIVE_OP` | Irreversible destructive operations: `rm -rf`, `git reset --hard`, `DROP TABLE`, `mkfs`, `dd if=` | +25 |
| `PROMPT_INJECT` | Embeds natural language directives targeting the AI agent, attempting to override its rules, bypass constraints, or assume an unrestricted persona | +35 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
| `AGENT_MEMORY` | Accesses agent memory files (identity, preferences, context) | +25 |
| `PKG_INSTALL` | Installs unlisted system packages or dependencies | +20 |
| `COOKIE_SESSION` | Reads browser cookies, localStorage, session tokens | +25 |
| `BYPASS_SAFETY` | Uses flags that skip security checks: `--no-verify`, `--force`, `--allow-root`, `--skip-ssl` | +20 |
| `DESTRUCTIVE_OP` | Irreversible destructive operations: `rm -rf`, `git reset --hard`, `DROP TABLE`, `mkfs`, `dd if=` | +25 |
| `PROMPT_INJECT` | Embeds natural language directives targeting the AI agent, attempting to override its rules, bypass constraints, or assume an unrestricted persona | +35 |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

md
CRED_HARVEST:
  (API_KEY|SECRET|TOKEN|PASSWORD|PRIVATE_KEY).*=|
  cat.*id_rsa|cat.*\.env|keyring\.get

PRIV_ESCALATION:
  sudo\s|chmod\s+[0-7]*7|chown\s+root|setuid

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
variable names all <3 chars in >20 occurrences

BYPASS_SAFETY:
  --no-verify|--force|--allow-root|--skip-ssl|--insecure|--no-check-certificate|
  GIT_SSL_NO_VERIFY|NODE_TLS_REJECT_UNAUTHORIZED=0

DESTRUCTIVE_OP:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
"commands": [
      {
        "tag": "EXEC_SHELL",
        "value": "rm -rf /tmp/traces",
        "file": "setup.sh",
        "line": 23,
        "context": "subprocess.run(['rm', '-rf', '/tmp/traces'], shell=True)"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
"commands": [
      {
        "tag": "EXEC_SHELL",
        "value": "rm -rf /tmp/traces",
        "file": "setup.sh",
        "line": 23,
        "context": "subprocess.run(['rm', '-rf', '/tmp/traces'], shell=True)"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
"commands": [
      {
        "tag": "EXEC_SHELL",
        "value": "rm -rf /tmp/traces",
        "file": "setup.sh",
        "line": 23,
        "context": "subprocess.run(['rm', '-rf', '/tmp/traces'], shell=True)"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 291)May include surrounding context.

md
"value": "rm -rf /tmp/traces",
        "file": "setup.sh",
        "line": 23,
        "context": "subprocess.run(['rm', '-rf', '/tmp/traces'], shell=True)"
      },
      {
        "tag": "EXEC_DYNAMIC",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 302)May include surrounding context.

md
},
      {
        "tag": "PRIV_ESCALATION",
        "value": "chmod 777 /usr/local/bin/hook",
        "file": "install.sh",
        "line": 11,
        "context": "os.system('chmod 777 /usr/local/bin/hook')"

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The skill explicitly states that evidence about accesses to sensitive paths such as '~/.ssh/id_rsa' may be extracted and uploaded as part of cloud analysis. Even if file contents are not sent, transmitting exact sensitive path usage and matched code lines can expose credential locations, internal implementation details, and highly sensitive security-relevant metadata to a third party by default.

Content

Scanner excerpt · SKILL.md (reported line 318)May include surrounding context.

md
},
      {
        "tag": "FS_READ_SENSITIVE",
        "value": "~/.ssh/id_rsa",
        "file": "auth.py",
        "line": 18,
        "context": "open(os.path.expanduser('~/.ssh/id_rsa')).read()"

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

This line shows the matched context for reading '~/.ssh/id_rsa', which the skill says can be included in uploaded single-line evidence. Sending code lines that reference private-key paths can leak sensitive operational details and may capture proprietary or security-sensitive logic.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
"value": "~/.ssh/id_rsa",
        "file": "auth.py",
        "line": 18,
        "context": "open(os.path.expanduser('~/.ssh/id_rsa')).read()"
      }
    ],
    "obfuscation_samples": [

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Conflicting descriptions of remote analysis are a real security-relevant issue because they affect informed consent and deployment decisions in restricted environments. Users may assume scans are local-only or mandatory-cloud when neither is consistently true, leading to unintended metadata exfiltration or false trust in protections.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

md
| `EXEC_DYNAMIC` | `eval()`、`exec()`、动态代码执行 |
| `ENCODE_DECODE` | Base64/Hex 编解码链(潜在混淆) |
| `CRED_HARVEST` | 从环境变量或文件读取 API Key、Token、密码 |
| `PRIV_ESCALATION` | `sudo`、`chmod 777`、`setuid` 等提权操作 |
| `OBFUSCATED` | 混淆/压缩代码、不可读变量名 |
| `AGENT_MEMORY` | 访问 Agent 身份/记忆文件 |
| `PKG_INSTALL` | 安装未声明的系统依赖包 |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.zh-CN.md (reported line 79)May include surrounding context.

md
| `EXEC_DYNAMIC` | `eval()`、`exec()`、动态代码执行 |
| `ENCODE_DECODE` | Base64/Hex 编解码链(潜在混淆) |
| `CRED_HARVEST` | 从环境变量或文件读取 API Key、Token、密码 |
| `PRIV_ESCALATION` | `sudo`、`chmod 777`、`setuid` 等提权操作 |
| `OBFUSCATED` | 混淆/压缩代码、不可读变量名 |
| `AGENT_MEMORY` | 访问 Agent 身份/记忆文件 |
| `PKG_INSTALL` | 安装未声明的系统依赖包 |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
| `EXEC_DYNAMIC` | `eval()`、`exec()`、动态代码执行 |
| `ENCODE_DECODE` | Base64/Hex 编解码链(潜在混淆) |
| `CRED_HARVEST` | 从环境变量或文件读取 API Key、Token、密码 |
| `PRIV_ESCALATION` | `sudo`、`chmod 777`、`setuid` 等提权操作 |
| `OBFUSCATED` | 混淆/压缩代码、不可读变量名 |
| `AGENT_MEMORY` | 访问 Agent 身份/记忆文件 |
| `PKG_INSTALL` | 安装未声明的系统依赖包 |

Static analysis

No suspicious patterns detected.