Back to skill

Security audit

FDE Skill

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real enterprise AI deployment skill, but it needs Review because it enables broad persistent tooling and data movement with unclear limits.

Install only if you intend to deploy the full sofagent enterprise/FDE stack, not just read a methodology skill. Before installing, review exactly what install.sh changes, which MCP clients it configures, whether daemon/webhook/data push/device registration features are enabled, and restrict tool roles to the minimum needed. Require human confirmation for USB creation, workflow activation, PR merge, training/model operations, device registration, and any data export or push path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (65)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · agents/engineer/SKILL.md (reported line 143)May include surrounding context.

md
- ❌ `npm publish`
- ❌ 修改 `.sofagent/` 目录
- ❌ 硬编码密钥、令牌
- ❌ `rm -rf` / `git reset --hard`

## 📋 范围自检(每次提交前使用)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document promises that all memory, logs, and decision records never leave the local device, but elsewhere describes automated exception push notifications and sustained monitoring. This contradiction can mislead operators about data flows and cause sensitive enterprise telemetry or audit metadata to be transmitted off-device without informed consent or proper controls.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · harness/entry-gate.md (reported line 20)May include surrounding context.

md
| 检查项 | 命令 | 权限边界 | OpenClaw | WorkBuddy | Web | 结果标注 |
|------|------|------|:--:|:--:|:--:|------|
| 编排 | `command -v sofagent-orchestrator` | 不可谎称编排可用 | ✅ | ⚠️ | ❌ | 编排=可用/手动 |
| bash | `command -v bash` | 不可 `rm -rf /`/删非项目文件/改系统配置/`curl\|bash` | ✅ | ⚠️ | ❌ | ✅/❌/N/A |
| git | `command -v git` | 不可 `push --force` 到 main/master/改 `.git/config` | ✅ | ⚠️ | ❌ | ✅/❌/N/A |
| jq/node | `command -v jq\|node` | — | ✅ | ⚠️ | ❌ | ✅/❌/N/A |
| 文件写入 | shell 判定 | 不可覆盖 `.git/`/`~/.ssh/`/宪法文件 | ✅ | ⚠️ | ❌ | ✅/❌/N/A |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · harness/entry-gate.md (reported line 20)May include surrounding context.

md
| 检查项 | 命令 | 权限边界 | OpenClaw | WorkBuddy | Web | 结果标注 |
|------|------|------|:--:|:--:|:--:|------|
| 编排 | `command -v sofagent-orchestrator` | 不可谎称编排可用 | ✅ | ⚠️ | ❌ | 编排=可用/手动 |
| bash | `command -v bash` | 不可 `rm -rf /`/删非项目文件/改系统配置/`curl\|bash` | ✅ | ⚠️ | ❌ | ✅/❌/N/A |
| git | `command -v git` | 不可 `push --force` 到 main/master/改 `.git/config` | ✅ | ⚠️ | ❌ | ✅/❌/N/A |
| jq/node | `command -v jq\|node` | — | ✅ | ⚠️ | ❌ | ✅/❌/N/A |
| 文件写入 | shell 判定 | 不可覆盖 `.git/`/`~/.ssh/`/宪法文件 | ✅ | ⚠️ | ❌ | ✅/❌/N/A |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although the command targets an application directory rather than the entire home directory, the use of rm -rf with a variable subpath remains hazardous and unnecessary as the primary rollback mechanism. The surrounding context does not add safeguards like resolved-path verification or user approval, which makes accidental destructive execution materially plausible.

Content

Scanner excerpt · harness/installer.md (reported line 58)May include surrounding context.

诊断表:

text
{ "step": 2, "status": "failed", "exitCode": 1, "stderrTail": "<最后 5 行>", "advice": "按 stderr 指路修复后重跑本步", "rollback": "rm -rf ~/.sofagent/<本版目录>(安装未完成时);已存在旧版则恢复备份" }

回滚:install.sh 迁移旧目录失败会自行中止(数据安全语义);Agent 侧只需确认 ~/.sofagent/ 状态与安装前一致(第 1 步检测时记的快照)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although the command targets an application directory rather than the entire home directory, the use of rm -rf with a variable subpath remains hazardous and unnecessary as the primary rollback mechanism. The surrounding context does not add safeguards like resolved-path verification or user approval, which makes accidental destructive execution materially plausible.

Content

Scanner excerpt · harness/installer.md (reported line 58)May include surrounding context.

诊断表:

text
{ "step": 2, "status": "failed", "exitCode": 1, "stderrTail": "<最后 5 行>", "advice": "按 stderr 指路修复后重跑本步", "rollback": "rm -rf ~/.sofagent/<本版目录>(安装未完成时);已存在旧版则恢复备份" }

回滚:install.sh 迁移旧目录失败会自行中止(数据安全语义);Agent 侧只需确认 ~/.sofagent/ 状态与安装前一致(第 1 步检测时记的快照)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although the command targets an application directory rather than the entire home directory, the use of rm -rf with a variable subpath remains hazardous and unnecessary as the primary rollback mechanism. The surrounding context does not add safeguards like resolved-path verification or user approval, which makes accidental destructive execution materially plausible.

Content

Scanner excerpt · harness/installer.md (reported line 58)May include surrounding context.

诊断表:

text
{ "step": 2, "status": "failed", "exitCode": 1, "stderrTail": "<最后 5 行>", "advice": "按 stderr 指路修复后重跑本步", "rollback": "rm -rf ~/.sofagent/<本版目录>(安装未完成时);已存在旧版则恢复备份" }

回滚:install.sh 迁移旧目录失败会自行中止(数据安全语义);Agent 侧只需确认 ~/.sofagent/ 状态与安装前一致(第 1 步检测时记的快照)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although the command targets an application directory rather than the entire home directory, the use of rm -rf with a variable subpath remains hazardous and unnecessary as the primary rollback mechanism. The surrounding context does not add safeguards like resolved-path verification or user approval, which makes accidental destructive execution materially plausible.

Content

Scanner excerpt · harness/installer.md (reported line 58)May include surrounding context.

诊断表:

text
{ "step": 2, "status": "failed", "exitCode": 1, "stderrTail": "<最后 5 行>", "advice": "按 stderr 指路修复后重跑本步", "rollback": "rm -rf ~/.sofagent/<本版目录>(安装未完成时);已存在旧版则恢复备份" }

回滚:install.sh 迁移旧目录失败会自行中止(数据安全语义);Agent 侧只需确认 ~/.sofagent/ 状态与安装前一致(第 1 步检测时记的快照)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · harness/loop-check.md (reported line 39)May include surrounding context.

md
🟢继续 / 🟡调整(子任务间→改下个子任务;60%→全量重编排剩余)/ 🔴暂停等确认。历史优先:有 Loop 记录时加倍检查最容易出问题的节点。

> ⛔ 重大操作前自检(约束回响):执行 rm / git reset / DROP / 外部 API 等不可逆操作前,先自问——当前生效的铁律有哪些?最近一条反思区记录是什么?如果答不上来,说明加载链已失效,暂停操作等用户确认。

> ⛔ **防雪崩**:共享状态(文件系统、git working tree、环境变量)被多个子任务并发修改,会导致 Agent「自己修自己改、越修越乱」。规则:
> 1. 子任务间必须显式标注共享状态变更——在 task/logs 中记录「修改了 X 文件/变量 Y」

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · harness/task-aware.md (reported line 28)May include surrounding context.

md
| 🟡 | 多步清楚/3-5文件 | 「收到。中途需要确认的问你。」 | ❌ |
| 🔴 | 模糊/多模块/高风险/犹豫 | 「涉及[简述],拆解一下?」→ 确认后澄清 | ✅ |

**硬信号强制 🔴**:文件删除/重构≥5个 | 破坏性操作(rm -rf/git reset/DROP)| 首次用新工具 | 用户提供Spec。硬信号>软判断,即使用户说「直接执行」。⛔ 🔴 后严禁自主扫描文件——仅输出 1.3 响应,等确认。

## 1.4 两轮澄清(仅 🔴 + 用户同意)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

L003 contains a hard constraint about how audit results must be presented and is written as a mandatory rule in Chinese, with no indication that users can choose language or locale. A skill should not force a specific language or locale without opt-in or a clearly documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation promotes an installation command that automatically writes MCP configuration files, which changes local developer environment state without an explicit warning, preview, or consent step. In agent/tooling ecosystems, silent config mutation can redirect tool trust, expand available capabilities, or persist access paths the user did not intend to enable.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The section beginning at L054 frames the audit agent as a compliance checker that runs once and reports results, but the same file later advertises access to a 104-tool MCP surface including entity creation/deletion, workflow mutation, PR merge, model training, device registration, and data push operations. For an auditor-oriented skill context, these capabilities are not justified by the stated audit purpose and materially expand what the agent ecosystem can do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description and all operational instructions are written as if the agent should operate in Chinese, but there is no statement offering the user a language choice or limiting the skill to a justified Chinese-only context. This can violate language or locale policy when applied to users who did not opt into Chinese interaction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and ambiguous, which can cause the skill to activate in contexts the user did not intend. In a skill that injects constraints, reads local files, and may invoke operational tooling, overbroad activation increases the chance of unintended file access, workflow steering, or tool usage based on weak contextual matches.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L035 states "不写应用代码" (do not write application code) as part of the agent's role. However, L170 instructs the agent to aggregate patterns into a skill and write it into ~/.sofagent/skill/custom/, which is code/artifact generation and persistence; this is an active contradiction in documented intent, not just an omitted detail.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad, common operational terms such as '审计' and '巡检', which can cause the skill to activate in contexts beyond strict compliance auditing. Because this skill delegates work via a Bash command to an orchestrator with the user's task passed through, unintended invocation increases the chance of unnecessary command execution and scope confusion across the agent system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is written entirely as mandatory Chinese instructions without offering a language option or documenting a hard locale requirement. In multilingual environments, this can lead to misinterpretation of safety-critical constraints, incorrect execution, or silent failure when the invoking system or operator does not reliably process Chinese.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases and scenarios are broad, generic coding requests such as bug fixing and feature implementation. In an agent-routing system, this can cause the skill to activate for many unrelated developer tasks, increasing the chance that its strong behavioral constraints override a more appropriate specialized skill or user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list contains broad enterprise phrases and generic workflow/deployment terms that can cause this powerful deployment skill to activate in situations beyond its intended scope. Because the skill can lead to orchestration, USB provisioning, and enterprise workflow changes, overbroad routing increases the chance of unnecessary or unsafe invocation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly instructs the agent to invoke Bash and hand user tasks directly to an orchestrator, which is still operational command execution triggered from natural-language input. In a deployment-oriented skill, this creates a real risk of unsafe or insufficiently reviewed command invocation, especially if task text is forwarded 'as-is' into downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The USB deployment section describes writing software, constraints, and encrypted enterprise knowledge onto removable media without an explicit warning, confirmation gate, or data-handling caution. In practice, this can lead to accidental overwrites, unintended propagation of sensitive business knowledge, or insecure physical distribution of a preconfigured execution environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill name, display name, and full description are entirely in Chinese, and the document consistently instructs behavior in Chinese without any opt-in or indication that the skill is intentionally limited to Chinese-speaking users. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation asserts a strict boundary that custom/ 'only manages rules, not code' and elsewhere says 'Agent itself: does not write'. However, later sections explicitly describe install/upgrade code paths that create directories, overwrite files, generate merge-conflict files, and write backups under custom/. This is an active contradiction in the file's stated intent versus described behavior, not merely an omission.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L041 explicitly says the agent reads custom/ but does not write it because the agent cannot self-modify behavior rules. Later lines describe concrete write operations affecting custom/, including overwrite with --force, backup creation in custom/.backup, merge outputs, and automatic directory creation. As written, the documentation presents mutually inconsistent claims about writes to custom/.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.