Back to skill

Security audit

Agent-Selector

Security checks for vulnerabilities and agentic risk

Overview

This skill advertises a read-only persona selector, but bundled personas can direct agents to publish publicly, schedule future work, and process payments without enough approval boundaries.

Review this package before installing in an environment with network, browser, scheduler, social-media, payment, or secret access. Do not provide Upload-Post, Gemini, or AgenticBTC credentials unless you have disabled or tightly sandboxed the high-impact personas and require explicit confirmation before every public post, scheduled run, or payment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
agency-agents/marketing/marketing-carousel-growth-engine.md:9
Finding

Autonomous External Publishing, Persistent State, and Scheduled Execution Without Per-Action Approval

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
agency-agents/specialized/accounts-payable-agent.md:9
Finding

Unpinned Runtime Installation of a Credentialed Payment MCP Server

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (233)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 88)May include surrounding context.

AgentSelector("agency-agents")

❌ 拒绝(抛出 ValueError)

AgentSelector("/etc/passwd") AgentSelector("../secret")

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

AgentSelector("agency-agents")

❌ 拒绝(抛出 ValueError)

AgentSelector("/etc/passwd") AgentSelector("../secret")

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · agency-agents/engineering/engineering-git-workflow-master.md (reported line 68)May include surrounding context.

bash
git fetch origin
git rebase -i origin/main    # 合并 fixup,修改提交信息
git push --force-with-lease   # 安全地强推到你的分支

完成分支

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · agency-agents/engineering/engineering-technical-writer.md (reported line 71)May include surrounding context.

md
## 为什么需要这个

<!-- 2-3 句话:这个项目解决什么痛点。不是功能列表——是痛点。 -->

## 快速开始

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · agency-agents/engineering/engineering-technical-writer.md (reported line 71)May include surrounding context.

md
## 为什么需要这个

<!-- 2-3 句话:这个项目解决什么痛点。不是功能列表——是痛点。 -->

## 快速开始

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Using curl with the -k flag disables TLS certificate validation, making the deployment vulnerable to man-in-the-middle interception or redirection. In this CI/CD context, that could expose Splunk credentials and allow an attacker to tamper with the rules being deployed to the SIEM.

Content

Scanner excerpt · agency-agents/engineering/engineering-threat-detection-engineer.md (reported line 341)May include surrounding context.

md
- name: 部署到 Splunk
        run: |
          # 通过 Splunk REST API 推送编译后的规则
          curl -k -u "${{ secrets.SPLUNK_USER }}:${{ secrets.SPLUNK_PASS }}" \
            https://${{ secrets.SPLUNK_HOST }}:8089/servicesNS/admin/search/saved/searches \
            -d @compiled/splunk/rules.conf

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · agency-agents/engineering/engineering-threat-detection-engineer.md (reported line 360)May include surrounding context.

通过 Azure CLI 部署

text
      az sentinel alert-rule create \
        --resource-group ${{ secrets.AZURE_RG }} \
        --workspace-name ${{ secrets.SENTINEL_WORKSPACE }} \
        --alert-rule @compiled/sentinel/rules.kql
text

### 威胁狩猎 Playbook

```markdown
# 威胁狩猎:通过 LSASS 获取凭证

## 狩猎假设
拥有本地管理员权限的攻击者正在使用 Mimikatz、ProcDump 或直接 ntdll 调用
从 LSASS 进程内存中转储凭证,而我们当前的检测未能覆盖所有变种。

## MITRE ATT&CK 映射
- **T1003.001** — 操作系统凭证转储:LSASS 内存
- **T1003.003** — 操作系统凭证转储:NTDS

## 所需数据源
- Sysmon Event ID 10 (ProcessAccess) — 带可疑权限的 LSASS 访问
- Sysmon Event ID 7 (ImageLoaded) — 加载到 LSASS 的 DLL
- Sysmon Event ID 1 (ProcessCreate) — 带 LSASS 句柄的进程创建

## 狩猎查询

### 查询 1:直接 LSASS 访问(Sysmon Event 10)

index=windows sourcetype

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs autonomous end-to-end posting to TikTok and Instagram without waiting for user approval, which creates a real risk of unauthorized public actions from connected accounts. In context, this is more dangerous because the workflow is designed to scrape a target URL, generate promotional assets, and immediately publish them externally, leaving little opportunity for a human to catch brand, legal, or reputational issues before posting.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs posts to be publicly visible and to automatically schedule future executions based on learned best times, without a prominent warning about persistent account impact or ongoing unattended automation. This materially increases danger because a one-time invocation can turn into repeated public posting behavior, amplifying the chance of spam, account penalties, accidental disclosure, or reputational damage.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The cleanup command constructs aws s3 rm against only the bucket prefix while taking object keys from a pipeline, creating a dangerous parameterization pattern. This is error-prone and can delete unintended objects or fail in unpredictable ways, especially if command output formatting, whitespace, or unexpected keys interact badly with the CLI invocation.

Content

Scanner excerpt · agency-agents/support/support-infrastructure-maintainer.md (reported line 399)May include surrounding context.

md
# S3 清理(生命周期策略应该已经处理了,这里做二次确认)
    aws s3api list-objects-v2 --bucket "$S3_BUCKET" \
        --query "Contents[?LastModified<='$(date -d "$RETENTION_DAYS days ago" -u +%Y-%m-%dT%H:%M:%SZ)'].Key" \
        --output text | xargs -r -n1 aws s3 rm "s3://$S3_BUCKET/"

    log "过期备份清理完成"
}

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The list-objects-v2 ... | xargs ... aws s3 rm chain is a hazardous shell composition for destructive operations. Chained parsing of CLI output into deletion commands can mis-handle whitespace, large result sets, empty values, or unexpected formatting, leading to unintended mass deletion or unreliable cleanup of backup data.

Content

Scanner excerpt · agency-agents/support/support-infrastructure-maintainer.md (reported line 399)May include surrounding context.

md
# S3 清理(生命周期策略应该已经处理了,这里做二次确认)
    aws s3api list-objects-v2 --bucket "$S3_BUCKET" \
        --query "Contents[?LastModified<='$(date -d "$RETENTION_DAYS days ago" -u +%Y-%m-%dT%H:%M:%SZ)'].Key" \
        --output text | xargs -r -n1 aws s3 rm "s3://$S3_BUCKET/"

    log "过期备份清理完成"
}

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
90% confidence
Finding

The helper function returns the full raw prompt content for any supplied agent_id, effectively exposing internal system prompts/persona instructions to callers. In an agent framework, prompts often contain privileged guidance, behavioral constraints, or proprietary logic, so direct extraction can enable prompt theft, reverse engineering, or downstream prompt-injection tailoring.

Content

Scanner excerpt · agent_selector.py (reported line 862)May include surrounding context.

python
selector = AgentSelector(agent_source)
    prompt = selector.load_agent_prompt(agent_id)
    print(f"✅ 已切换到 {agent_id} 人格")
    return prompt


# ============================================================================

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The primary title and the surrounding documentation are presented in Chinese, and the file does not indicate that users can choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At L038 the documentation says the skill package already contains the complete agency-agents directory and needs no extra symlink configuration. However, L231-L233 later state that users must manually create an agency-agents symlink pointing to agency-agents-zh, which is a direct contradiction in the documented setup and affects the skill's actual file access assumptions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is described as a global capability that automatically switches among many expert personas based on conversation context, with task-end detection and automatic reversion. Without narrowly defined activation criteria, scope limits, or explicit user confirmation, it can over-apply hidden behavioral changes and influence unrelated interactions, creating prompt-scope confusion and unsafe autonomy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is explicitly presented as a Chinese-only version ('中文版', '翻译并本土化') and all usage guidance is written solely in Chinese, but it does not offer an alternative language option or state that the locale restriction is optional for users. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This README provides invocation examples such as '激活前端开发者模式,帮我审查这个组件' and '使用前端开发者智能体帮我审查这个组件' as activation guidance, but it does not define a bounded list of accepted triggers, exclusions, or when these phrases should or should not activate a skill. Because these phrases overlap with normal user requests for help or code review, they risk unintended invocation in tools that rely on natural-language matching.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire document is written in Chinese and describes translated and China-market-specific agents, but it does not indicate that language or locale is optional or scoped to a region-specific distribution. Under the policy, forcing a specific language without user opt-in or clear justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction states that on social media the form of address must remain '您' and cannot be changed to '你'. This imposes a specific language/register policy as a hard rule without indicating user opt-in or a justified region-specific constraint, which matches the locale/language policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, instructions, workflow, and templates are all written exclusively in Chinese, and there is no indication that the user may choose another language. Under the policy, a skill that effectively imposes a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill’s name, description, and all operating instructions are written entirely in Chinese, with no indication that users may choose another language or that the skill is region-specific. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is written entirely in Chinese and strongly frames the agent persona, workflow, and communication style in that language without indicating that language should follow user preference. This can cause the agent to ignore or override the user's requested locale, reducing usability, creating misunderstandings, and increasing the chance that downstream design or accessibility requirements are miscommunicated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata and body are written entirely in Chinese, which effectively forces a specific language/locale without any user opt-in or fallback behavior. This can cause user misunderstanding, incorrect task execution, or exclusion of users expecting another language, especially in multi-agent workflows where downstream agents assume prompts are user-aligned.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s name, description, and all operating instructions are written exclusively in Chinese, and the communication style examples also assume Chinese output. There is no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown skill file presents the role name, description, instructions, and workflow exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.