Back to skill

Security audit

国际关系辅助

Security checks for vulnerabilities and agentic risk

Overview

The main skill is an international-relations analysis prompt, but the package also ships unrelated executable file-processing scripts that are not disclosed by the skill description.

Review this before installing because the IR analysis prompt is accompanied by unrelated local-file utilities. They do not appear malicious or automatically invoked, but the publisher should either remove them or clearly document why they are included and when they should be run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向国际关系与比较政治内容分析的技能,即应当提供外交/安全/身份政治等领域的实质性分析能力。但实际代码并不进行任何国际关系推理、比较政治分析或地缘战略评估;它只是一个研究资料合并与摘要生成工具。其主要行为是读取本地 markdown 文件、统计 URL 和文本标记、提取标题、检测显式“矛盾”词,并输出汇总表。这与声明的核心用途在主目的和能力上都明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose says the skill supports international relations and comparative politics analysis. However, the supplied code does not implement any IR reasoning, policy analysis, identity analysis, or geopolitical evaluation. Its primary and only observable function is validating generated SKILL.md files against Phase 4 quality criteria. This is a materially different purpose, not a supporting implementation detail of an IR analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose describes a substantive international relations analysis skill for geopolitical and comparative politics tasks. However, the supplied code performs only subtitle cleaning and transcript generation from SRT/VTT files. Its primary purpose, inputs, outputs, and operational domain are entirely different from IR analysis. No part of the code implements international relations reasoning, policy analysis, comparative political analysis, or related domain-specific functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements subtitle conversion and local file I/O even though the declared skill is for international-relations analysis. This capability mismatch is dangerous because unrelated file-manipulation utilities increase the agent's attack surface and can be used to justify unexpected access to local user files under a misleading skill identity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill for international relations analysis, but this file is a utility that merges six agent research markdown files into a summary table for a review checkpoint. Its code performs local file aggregation and heuristic markdown parsing for a research workflow, which does not implement or directly support the declared IR-analysis capability in any domain-specific way.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script claims to automatically verify whether a generated SKILL.md passes 'Phase 4 quality standards', but the concrete checks are for items such as '心智模型', '表达DNA', '诚实边界', and '一手来源占比'. For a skill described as an international-relations analysis assistant, these are generic persona/template QA constraints rather than behavior or capability checks tied to international-relations analysis, creating a semantic mismatch between the stated skill purpose and what this code actually validates.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/quality_check.py (reported line 10)May include surrounding context.

python
python3 quality_check.py <SKILL.md路径>

示例:
    python3 quality_check.py .claude/skills/elon-musk-perspective/SKILL.md
"""

import sys

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Within an international-relations analysis context, adding subtitle format conversion is functionally unnecessary and broadens available capabilities beyond the user's likely expectations. Even if the script is not overtly malicious, irrelevant file-conversion code can facilitate data handling outside the declared mission and makes misuse or covert staging of local content easier.

Content

No source excerpt is available for this finding.

Tainted flow: 'transcript' from pathlib.Path.read_text (line 96, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/srt_to_transcript.py (reported line 98)May include surrounding context.

python
else:
        transcript = clean_srt(content)

    output_path.write_text(transcript, encoding='utf-8')

    # 统计
    word_count = len(transcript)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains natural-language instructions, usage text, and output messages only in Chinese, including the module docstring and runtime prompts. Under the policy rule, forcing a specific language without opt-in or a documented region-specific reason is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language strings and documentation entirely in Chinese, including the module docstring and usage example. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script prints usage, error, and result messages only in Chinese during execution. Because the file does not offer a locale choice or explain a justified region-specific constraint, this appears to enforce a single language for end users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.