Back to skill

Security audit

simaguang-perspective

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it gives a broad persona workflow persistent influence over future agent behavior and local learning files without tight user control.

Install only if you want this skill to act as a broad, persistent persona and learning system, not just a temporary analysis style. Review and consider disabling the ~/.codex learning writes, broad triggers, forced identity rules, and automatic/background maintenance workflows before using it in normal Codex sessions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (151)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs writing to a home-directory path outside the project workspace (~/.codex/lessons/LESSONS.md) without prominently warning the user. Writing outside the workspace is more dangerous because it affects persistent global state, may bypass expected repository review, and can contaminate future agent behavior across projects.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list includes broad, everyday phrases such as '全面分析' and '帮我决策', which can cause the skill to activate in many unrelated conversations. In this skill, accidental activation is more concerning because it imposes a strong persona, hidden file-reading workflow, and cross-domain decision framing that may override user expectations and route normal requests into an unintended analysis mode.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reasoning/persona aid, but the specification embeds many operational behaviors such as file reads/writes, report generation, routing maintenance, testing, audits, and script execution. This mismatch is dangerous because users and orchestrators may invoke a seemingly harmless analytical skill that actually performs repository or local-environment actions outside the declared purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.