Back to skill

Security audit

Secure Linter

Security checks for vulnerabilities and agentic risk

Overview

This is a small static code-review helper with disclosed security-linting behavior and no executable payload, persistence, or hidden privilege request.

Installers should know this skill may consult external security references while reviewing code. It appears safe as a lightweight static-review aid, but users handling private code should ensure the agent does not send sensitive snippets, secrets, or proprietary details to external pages or searches.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes the skill entirely in Chinese and presents its behavior/output conventions in Chinese without indicating that users may choose another language. This is a natural-language locale policy issue because it imposes a specific language by default with no opt-in or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and all user-facing instructions are written only in Chinese, and the output format specifies Chinese risk labels without any opt-in or alternative language option. This creates a language policy concern because the skill appears to enforce a specific locale regardless of user preference.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition '当用户要求审查代码时' is overly broad and can activate for ordinary code-review requests, not just security linting. Overbroad activation can cause the skill to run in unintended contexts, potentially applying network-enabled behavior or security-focused handling where it was not requested, increasing attack surface and the chance of unsafe tool use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is a local code-review/linting assistant, but it explicitly instructs the agent to use browser or web_fetch to consult external security guides. This expands the skill’s capability surface to network access without a clear necessity, creating risks such as unintended data exfiltration, prompt-injection exposure from fetched pages, or privacy leakage if code context is sent outward.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.