Back to skill

Security audit

Local LLM Setup Advisor

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for local LLM setup advice, with some weak routing and evidence-quality issues but no hidden execution, persistence, credential handling, or destructive behavior.

This skill is safe to install as an advisory local-LLM helper, but users should treat its demand-evidence claims cautiously and be aware that its broad implicit triggers could route some adjacent AI, privacy, or workflow questions to this skill unnecessarily.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

文件名和全文内容表明该技能为中文版本,但文档中没有说明这是可选语言,亦未提供用户可切换语言/locale 的提示。按规则,若技能强制特定语言而无用户 opt-in 或明确的地域合规理由,属于自然语言策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentence is broad enough that normal user requests about local AI workflows could activate the skill without clear boundaries, increasing the chance of unintended routing. In agent systems, ambiguous activation can cause the wrong skill to handle requests, which may bypass more appropriate safeguards or produce misleading outputs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README asserts 'validated demand' for local LLM setup guidance, but the cited links are unrelated to that topic. This is a documentation integrity problem that can mislead users, reviewers, or routing systems into trusting and invoking the skill under false pretenses, weakening governance over which skills are surfaced.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger sentence begins with a very broad phrase ('Help me ...'), which risks accidental or overly permissive activation if a platform uses naive matching. In an agent ecosystem, broad triggers can cause the wrong skill to run on unrelated requests, exposing users to unintended instructions or enabling prompt-scope hijacking.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and partially templated, which increases the chance that the skill is invoked for loosely related requests rather than explicit user intent. In an agent environment, unintended invocation can cause the wrong workflow to run, leading to confused task routing, accidental disclosure of irrelevant guidance, or bypass of more appropriate safety checks in other skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to activate on generic requests for workflows, analysis, or implementation support, not just clearly scoped local-LLM setup tasks. Over-broad triggering can cause unintended routing, letting this skill intercept unrelated user requests and influence outputs outside its intended domain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example trigger phrases use common language such as 'Help me' and 'I need a practical workflow,' which can match many ordinary requests if the dispatcher relies on semantic similarity. This increases the chance of accidental invocation and prompt-scope overreach, especially in systems that auto-select skills from natural-language examples.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description and activation scope are broad enough that ordinary requests about software, privacy, or local AI could trigger this skill even when the user did not intend to invoke it. Overbroad routing can cause incorrect skill selection, irrelevant guidance, or unintended disclosure of context to the wrong skill, though it does not directly enable code execution or privilege escalation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The keyword list includes broad terms such as privacy and software-and-data that can appear in many unrelated conversations. This increases the chance of accidental activation and misrouting, which can degrade security boundaries between skills if downstream skills receive user context they should not have handled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrases begin with very generic requests like 'Help me' and 'I need a practical workflow,' which overlap with normal user prompts. If the routing system uses these examples as activation guidance, the skill may be selected for unrelated tasks, leading to confusion and broader-than-intended access to user queries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default invocation prompt is generic and broad, which can cause the skill to be selected in situations beyond its intended scope. Overly permissive activation text increases the chance of unintended routing, where the skill may influence responses for loosely related software or AI questions without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Enabling implicit invocation without clear trigger constraints allows the skill to activate automatically in ambiguous contexts. This expands the skill's effective authority and can lead to misrouting, unexpected behavior, or inappropriate guidance being inserted into unrelated conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The activation examples do not define clear boundaries between in-scope and out-of-scope requests, so the skill may be invoked for adjacent but unintended topics. This ambiguity increases prompt-routing risk and can lead to overbroad skill activation across ordinary conversations mentioning software, GPUs, privacy, or local workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file lists English and Chinese instruction and guide files, but does not state how the user's preferred language is selected. This can create a locale-handling policy concern if the skill defaults to a language without explicit user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This Chinese README includes key user-facing content in English, such as the requirement description, which can impose a language expectation without user opt-in. The document does not state that mixed-language output is intentional or provide an option for users to choose their preferred language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.