Back to skill

Security audit

ideas

Security checks for vulnerabilities and agentic risk

Overview

This is a simple local idea-tracking skill, with some usability and disclosure gaps but no evidence of hidden access, exfiltration, or unsafe execution.

Installers should understand that ideas may be saved locally and can be deleted by the skill. Use explicit commands when recording or deleting ideas, and confirm the actual storage path before relying on backups or privacy assumptions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrases are very broad everyday expressions such as '灵感', '发现', and '想法', which can easily match normal conversation and cause unintended activation. In this skill, unintended activation is more concerning because the documented behavior includes persistent local writes, status changes, and deletion-related operations on a user data file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly stores records in a persistent local path and supports deletion behavior, but it does not clearly warn users that their content will be written to disk or explain the difference between soft delete and permanent deletion. This creates privacy and integrity risk: users may disclose sensitive ideas without realizing they are being persisted, and may also unintentionally lose data through destructive operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The only user-facing output is a Chinese-language message, which imposes a specific language without any opt-in or alternative. This can violate language/locale policy when the skill is not clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.