Back to skill

Security audit

Data Recovery Assistant

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended for data recovery, but it should be reviewed because it gives root-level disk repair and hardware-repair guidance that could worsen data loss if used incorrectly.

Review this skill before installing. It is not showing deception or exfiltration, but data recovery advice can cause irreversible damage: only run commands after confirming the exact source device, avoid writes to the failing/source disk, recover from a clone or image where possible, and use a professional service for clicking, non-spinning, water-damaged, or dropped drives.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad, generic terms such as '文件丢失', '硬盘坏了', and '恢复数据', which are likely to appear in ordinary support conversations outside the intended scope. This can cause the skill to activate unexpectedly and steer an agent into specialized recovery guidance when the user may only be describing symptoms, increasing the chance of inappropriate or unsafe advice in a sensitive data-loss context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file provides direct disk-recovery commands and even hardware-action guidance such as swapping a PCB, but it does not prominently warn users to verify the target device, work from clones/images, and stop if hardware failure is suspected. In a data-recovery skill, incorrect execution on the wrong disk or repeated power-on of a failing drive can permanently worsen data loss or damage the device.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

The document instructs users to run ddrescue with sudo against a raw block device, which requires elevated privileges and can affect the wrong disk if misidentified. In this recovery context the command is legitimate, but presenting it without privilege minimization and device-verification safeguards creates a real risk of destructive operator error.

Content

Scanner excerpt · references/fault-reference.md (reported line 28)May include surrounding context.

bash
# ddrescue 创建镜像
sudo ddrescue -d /dev/sda /mnt/backup/image.img /mnt/backup/logfile.log

# 查看SMART信息
sudo smartctl -a /dev/sda

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/fault-reference.md (reported line 31)May include surrounding context.

md
sudo ddrescue -d /dev/sda /mnt/backup/image.img /mnt/backup/logfile.log

# 查看SMART信息
sudo smartctl -a /dev/sda

# TestDisk 修复分区表(交互式)
sudo testdisk /dev/sda

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/fault-reference.md (reported line 37)May include surrounding context.

md
sudo ddrescue -d /dev/sda /mnt/backup/image.img /mnt/backup/logfile.log

# 查看SMART信息
sudo smartctl -a /dev/sda

# TestDisk 修复分区表(交互式)
sudo testdisk /dev/sda

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The document recommends running TestDisk as root directly against /dev/sda to repair partition structures, which can modify on-disk metadata. In a data-recovery setting, encouraging privileged repair on the original disk without first imaging it can cause irreversible corruption or make professional recovery harder.

Content

Scanner excerpt · references/fault-reference.md (reported line 34)May include surrounding context.

md
sudo smartctl -a /dev/sda

# TestDisk 修复分区表(交互式)
sudo testdisk /dev/sda

# 查看分区信息
sudo fdisk -l /dev/sda

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Natural-language instructions and user-facing description appear to force a specific language/locale without stating that the user can choose another language. This can violate language-choice policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

All user-facing instructional content in this file is presented only in Chinese, and there is no indication that the user can choose another language or that the skill is explicitly limited to a Chinese-speaking audience. The policy calls for flagging forced language/locale behavior unless there is opt-in or a clearly justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.