Back to skill

Security audit

工作日/周/月/年报总结

Security checks for vulnerabilities and agentic risk

Overview

This is a local work-report generator with disclosed report-history reuse and local storage, though users should notice its broad trigger wording and automatic history reads.

Install this only if you are comfortable with a report helper reading prior reports from .workbuddy/reports/ to build summaries. Review drafts before approving saves, and avoid putting highly sensitive business or personnel details in stored reports unless that reuse is intended.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger definition is overly broad and includes language like arbitrary related input, which can cause the skill to activate on normal conversation unintentionally. In this skill's context, unintended activation is risky because activation can lead to automatic reading of local historical reports and generation based on prior sensitive work content the user did not freshly request.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger table allows activation from broad natural-language rambling and unconstrained keywords, which makes invocation rules vague and prone to false positives. In combination with the skill's automatic history-reading behavior, this increases the chance of surfacing prior sensitive work reports in contexts where the user only mentioned related phrases casually.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file mandates a specific colloquial Chinese output style as a required rule, but does not present a user language or locale choice in the active behavior. A forced language/style constraint can violate language/locale policy when users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Defaulting ambiguous keyword input to a daily report creates unclear activation boundaries and can cause the skill to act when the user did not intend to generate or persist a report. Because this skill also stores and reuses report content, accidental invocation can expose or memorialize sensitive work details unnecessarily.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to automatically read and reuse prior reports from local storage without a fresh disclosure or confirmation step. Those reports can contain sensitive business context, incidents, vulnerabilities, timelines, or personnel details, so automatic reuse may reveal prior private data in a new response even when the user only provided minimal new input.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

L163-L170 instructs the skill to read historical reports automatically and '静默进行', while L327 explicitly says that if historical reading fails, the user must be informed and the skill must not silently skip it. These instructions describe opposite intended behaviors for the same situation, creating intent ambiguity in the skill specification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.