Back to skill

Security audit

Typed Ontology Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malware, but parts of its localized instructions broaden an ontology helper into generic productivity, bug-fixing, and code-change guidance with implicit activation enabled.

Install only if you want an ontology and typed knowledge-graph workflow helper. Review or narrow SKILL.zh-CN.md and references/requirement-plan.md before enabling implicit routing, especially in agents that may act on bug-fix, hardening, implementation, or adjacent-skill requests.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest description does not match the stated skill purpose and instead advertises a generic 'validated demand' helper. This kind of semantic mismatch can cause the wrong skill to be invoked, leading agents or users to trust outputs from a capability that is not actually what was requested, which is a security-relevant integrity problem in agent routing and tool selection.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The title and body describe materially different functions: the title promises ontology/typed workflow help, while the body documents a generic demand-validation and workflow-adaptation process. This discrepancy undermines operator and agent trust, increases the chance of mis-execution, and can be abused to smuggle broader behavior under a benign-looking skill name.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The requirement plan materially broadens the skill from ontology and knowledge-graph design into generic bug-fixing, hardening, reliability, and adjacent-skill creation. This creates specification drift that can cause the agent to activate or respond outside its declared purpose, undermining user trust and increasing the chance of unsafe or irrelevant actions.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The executable plan is a generic productivity workflow rather than an ontology-specific procedure, so the operational behavior promised by the file does not align with the skill's declared domain. In practice, this can lead to overbroad task handling, unintended invocation for unrelated work, and weaker safety review because the implementation surface is less constrained than advertised.

Description-Behavior Mismatch

Low
Confidence
82% confidence
Finding
The expected outputs are generic artifacts like checklists and tailored answers instead of concrete ontology deliverables such as schemas, typed entities, relation maps, validation rules, or query templates. This mismatch is less severe than execution-plan drift, but it still weakens scoping and can cause users or orchestrators to rely on the skill for broader work than intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are overly broad and overlap with common technical discussion terms like 'knowledge', 'graph', 'structured', and 'bug fix'. Broad activation criteria can cause accidental invocation in unrelated contexts, exposing user data or causing an agent to follow an irrelevant workflow that alters outputs or decisions unexpectedly.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The enablement conditions in the description are vague and do not clearly define when the skill should or should not be used. In agent systems, ambiguous routing criteria can lead to incorrect tool use, expanding the skill's effective authority beyond its intended domain and reducing predictability and safety.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Overly broad trigger sentences increase the chance that the skill is activated by ordinary language unrelated to its narrow declared purpose. In an agent environment, this can cause prompt routing mistakes, accidental takeover of tasks outside domain expertise, and expansion of the skill's effective authority beyond what reviewers intended.

Static analysis

No suspicious patterns detected.