Back to skill

Security audit

清空废纸篓

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear trash-emptying purpose, but it requests broad destructive shell authority and explicitly skips confirmation for irreversible deletion.

Install only if you are comfortable letting the agent permanently empty your trash/recycle bin when invoked. Review the command carefully, especially on Linux, and prefer a version that narrows allowed tool arguments and asks for explicit confirmation before deleting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

Using 'rm -rf ~/.local/share/Trash/*' grants a powerful recursive deletion primitive through a broad shell command. Although intended to empty trash, shell expansion and path-handling risks make this more dangerous than a purpose-built API call, and any mistake in execution context or path resolution can cause irreversible data loss.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Linux(自动检测)

bash
rm -rf ~/.local/share/Trash/*

Windows(自动检测)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

Using 'rm -rf ~/.local/share/Trash/*' grants a powerful recursive deletion primitive through a broad shell command. Although intended to empty trash, shell expansion and path-handling risks make this more dangerous than a purpose-built API call, and any mistake in execution context or path resolution can cause irreversible data loss.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Linux(自动检测)

bash
rm -rf ~/.local/share/Trash/*

Windows(自动检测)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly performs irreversible deletion and states that no second confirmation is needed, relying solely on presumed user intent. For a destructive filesystem action, this removes an important safety barrier and increases the chance of accidental data loss from mis-triggering, ambiguous prompts, or user misunderstanding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description presents the skill primarily in Chinese and includes Chinese trigger phrases, without indicating that users may choose another language or locale. This can constitute a language/locale policy issue when the skill appears to assume a fixed language rather than offering user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.