Back to skill

Security audit

One Click Posting

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it needs review because its public-posting approval gate can be bypassed or fail as documented.

Install only after reviewing the approval workflow. Treat packet approval and preflight status as advisory until --allow-unapproved is removed or isolated to tests, the documented preflight command works, and downstream publishing always separately verifies explicit user approval before posting publicly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_preflight.py:13
Finding

Mandatory User-Approval Gate Can Be Explicitly Bypassed

Content
View full analysis
argparse.Namespace: parser = argparse.ArgumentParser(description="Run preflight checks on a publish packet") parser.add_argument("--packet", required=True, help="Path to packet JSON") parser.add_argument("--write-back", action="store_true", help="Write check results back to packet") parser.add_argument("--json", action="store_true", help="Print JSON report") parser.add_argument("--allow-unapproved", action="store_true", help="Allow pass even when approval.granted=false") return parser.parse_args() ``` ```python def evaluate(packet: dict, require_approval: bool): preflight = packet.get("preflight", {}) approval = packet.get("approval", {}) publish = packet.get("publish", {}) content = packet.get("content", {}) quality = preflight.get("quality_checks", {}) checks = { "deai_checked": bool(preflight.get("deai_checked")), "risk_reviewed": bool(preflight.get("risk_reviewed")), "source_traceable": bool(preflight.get("source_traceable")), "platforms_present": bool(publish.get("platforms", [])), "title_present": bool(content.get("title")), "approval_granted": (not require_approval) or bool(approval.get("granted")), } ``` ```python def main() -> None: args = parse_args() path, packet = load_packet(args.packet) report = evaluate(packet, require_approval=not args.allow_unapproved) ``` ### Technical Analysis The Skill documentation defines explicit user approval as a hard publishing boundary. However, `run_preflight.py` exposes the production command-line option `--allow-unapproved`, which changes `require_approval` to `False`. When this option is supplied, the following expression succeeds regardless of the store ...[truncated 1818 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:69
Finding

Mandatory Preflight Command Uses an Unsupported Argument

Content
View full analysis
argparse.Namespace: parser = argparse.ArgumentParser(description="Run preflight checks on a publish packet") parser.add_argument("--packet", required=True, help="Path to packet JSON") parser.add_argument("--write-back", action="store_true", help="Write check results back to packet") parser.add_argument("--json", action="store_true", help="Print JSON report") parser.add_argument("--allow-unapproved", action="store_true", help="Allow pass even when approval.granted=false") return parser.parse_args() ``` ### Technical Analysis The documented mandatory command includes `--require-approval`, but the implementation only supports the inverse option, `--allow-unapproved`. Python's `argparse` therefore rejects the documented command as containing an unrecognized argument and exits before performing any preflight checks. The immediate behavior is fail-closed rather than a direct authorization bypass. Nevertheless, the inconsistency makes the declared security control unusable as documented and can prompt operators or automation authors to omit, replace, or work around the preflight stage. ### Attack Path 1. An operator or automation process follows the mandatory command in `SKILL.md`. 2. `argparse` encounters the unsupported `--require-approval` option. 3. The process exits before `load_packet()` and `evaluate()` are executed. 4. No approval, qu ...[truncated 726 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding becomes security-relevant because the skill exposes local approval/status mutation behavior while lacking declared permissions and while presenting itself as a fully gated publishing workflow. In practice, that can mislead operators into trusting approval and state fields as evidence of completed controls, creating an integrity risk around publication readiness and audit records.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This finding becomes security-relevant because the skill exposes local approval/status mutation behavior while lacking declared permissions and while presenting itself as a fully gated publishing workflow. In practice, that can mislead operators into trusting approval and state fields as evidence of completed controls, creating an integrity risk around publication readiness and audit records.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs reading and writing local files such as body content, publish packets, screenshots, and archives, but it declares no explicit tool scope or permissions boundaries. That creates an authorization gap where an agent may access or modify files without a clearly constrained contract, increasing the risk of unintended file exposure or tampering if the skill is invoked in a broader environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough that ordinary requests like '帮我直接发' or '多平台同步发' could invoke a high-impact posting workflow unintentionally. In this context, accidental invocation is more dangerous than usual because the skill is designed to prepare or initiate public posting actions and to read/write related local artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and frames invocation using Chinese command phrases, but it does not indicate that language choice is optional or that the skill is intentionally limited to a Chinese-language environment. This can conflict with language/locale policy when no user opt-in or documented justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code enforces Chinese-only values for --verify-status and later emits multiple Chinese warning strings, which creates a language/locale restriction in the skill's user-facing behavior. Because there is no opt-in, fallback language, or documented region-specific justification in this file, it fits the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file's operational instructions and headings are all in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.