Back to skill

Security audit

Dev Tools

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed developer toolbox for code checks, reports, dependency analysis, and optional user-invoked refactoring, with no hidden exfiltration, persistence, or destructive behavior found.

Install only if a Chinese-language developer-tool workflow fits your environment. Before using refactor --apply or debt/spec commands, review the intended file changes; before running the boundary-check shell script, set PROJECT_ROOT carefully because it scans the working tree and writes a timestamped report under docs/boundary-checks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill title and the entire usage documentation are presented only in Chinese, with no indication that users may choose another language or locale. This can violate a language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the main skill documentation are written entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's user-facing comments and help/output strings are written in Chinese, and the help text shown to users is only provided in Chinese later in the file. This imposes a specific language on users without opt-in or any documented justification that the tool is intended only for a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The prompt is written as a direct role instruction in Chinese and does not state that the assistant should match the user's preferred language or offer a language choice. This can violate language/locale policy because it implicitly constrains interaction language without user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

refactor --apply expands the skill from advisory analysis into state-changing code modification, but the prompt frames the feature primarily as suggestion generation. That mismatch can cause an agent or user to invoke a seemingly safe analysis tool and unexpectedly mutate the codebase, bypassing intended review or approval checkpoints. In a developer-tool skill, hidden or under-emphasized write capabilities are more dangerous because they can directly alter source code or introduce insecure refactors at scale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The boundary section says the skill must not trigger for codebase analysis, yet the documented dep subcommand performs dependency analysis across modules/services. This inconsistency can cause policy routing errors where an agent selects the wrong skill, skips deeper review paths, or applies weaker safeguards than intended. The issue is contextual rather than directly exploitative, but it increases the chance of unsafe or unauthorized analysis behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The boundary documentation contradicts the earlier capability definitions for both dep and refactor, creating ambiguous operational scope. Contradictory instructions in an agent skill are security-relevant because they can be exploited through prompt steering: a user can selectively cite the permissive section to trigger analysis or refactoring outside intended guardrails. In this context, the danger is from confused-deputy behavior rather than direct code execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.