Back to skill

Security audit

Windows Shell Encoding Doctor - Windows Shell编码修复工具

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only troubleshooting skill for Windows shell and encoding problems, with no hidden execution or persistent behavior found.

Before installing, expect this skill to steer the assistant toward Windows shell troubleshooting and to suggest commands that may write local UTF-8 files or normalize line endings. Review any generated command before running it, especially if it writes files, changes encodings, or converts line endings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/repair-playbooks.md (reported line 24)May include surrounding context.

md
- Confirm whether the shell is PowerShell.
- If yes, strongly suspect bash heredoc syntax pasted directly into PowerShell.
- Do not blame Python / Node / curl first.

### Fix strategy

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction "If the user is on PowerShell, return a PowerShell-first answer" imposes a tool/locale-style output preference unilaterally rather than offering a choice. Under the policy, forcing a specific language or locale-style response without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs activation on the very broad phrase “it broke, how do I fix it?”, which can cause this skill to trigger in many unrelated contexts. Over-broad invocation increases the chance the agent routes users into shell/encoding guidance when they did not ask for it, potentially causing unsafe or irrelevant command advice to be surfaced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The phrase "prefer temp files if JSON or Chinese text is involved" singles out a specific language in the recommended response shape. This can be read as special-casing Chinese-language content without offering a user choice or clearly documenting a justified locale-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.