Back to skill

Security audit

SKILL审查

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed skill-review helper with limited local scripts; its optional auto-fix behavior is narrow and purpose-aligned.

Install only if you are comfortable with a Chinese-language skill that can run local Python scripts against a skill directory. Use the single-pass analyzer for read-only review; run the review-loop only when you want it to create missing standard directories in the target skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose says the skill is for review and optimization guidance, but the body includes behaviors that can execute scripts, iterate review-fix loops, and potentially modify the target skill directory. This mismatch is dangerous because users or orchestration layers may treat the skill as advisory while it actually performs write-capable or autonomous actions on the filesystem.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
- 目录必须包含 `SKILL.md` 文件

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description, headings, trigger phrases, and workflow are all presented only in Chinese, which implies a fixed language requirement. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs use of code-capable actions such as reading files and running shell commands, but it does not declare any tool scope or allowed-tools boundary. That creates an authorization ambiguity where an agent may invoke broader capabilities than users expect, increasing the chance of unsafe file-system inspection or command execution during review tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's user-facing description is written entirely in Chinese and specifies its activation/use context in Chinese, with no indication that other languages are supported or that the user can choose a preferred language. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest uses Chinese for the skill name, description, and category, with no indication that language selection is optional or that the skill is intended only for a Chinese-language environment. This can violate a language/locale policy when users are not given an explicit opt-in or documented justification for the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill reference is written as a prescriptive template in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Per the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s docstring, usage text, comments, and generated report strings are all hard-coded in Chinese, indicating the skill operates in a specific language by default. The policy allows locale constraints only when user choice or clear justification is provided, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring presents the script description, usage, and examples entirely in Chinese, and all user-facing output strings in the file are likewise Chinese-only. This constitutes a language-policy issue because the skill hardcodes a single language without offering a user opt-in or documenting that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains all docstrings, help text, status messages, and error messages in Chinese, including the CLI description and runtime output. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/review-loop.py (reported line 27)May include surrounding context.

python
(是否有问题, 输出内容)
    """
    script_path = Path(__file__).parent / "analyze.py"
    result = subprocess.run(
        [sys.executable, str(script_path), str(skill_path)],
        capture_output=True,
        text=True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/review-loop.py (reported line 49)May include surrounding context.

python
(是否有问题, 输出内容)
    """
    script_path = Path(__file__).parent / "analyze.py"
    result = subprocess.run(
        [sys.executable, str(script_path), str(skill_path)],
        capture_output=True,
        text=True

Static analysis

No suspicious patterns detected.