Back to skill

Security audit

Yichen Trash Bag

Security checks for vulnerabilities and agentic risk

Overview

The customer-service skill content is mostly coherent, but its installers add unattended auto-updates and execute mutable remote code in ways users should review carefully before installing.

Install only after reviewing the scripts locally. Prefer a pinned release or verified archive, avoid running the one-line remote shell commands, and remove or decline the cron/scheduled-task auto-update behavior unless you explicitly want the skill to update itself every day from GitHub. Do not run the installer with administrator or root privileges.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:31
Finding

Unverified Remote Installer Is Executed Directly by the Shell

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
install.sh:47
Finding

Unix Installer Establishes Unattended Daily Code Updates Through Cron

Content
View full analysis
/dev/null || git pull --ff-only origin master 2>/dev/null" if ! crontab -l 2>/dev/null | grep -q "yichen-trash-bag"; then (crontab -l 2>/dev/null; echo "7 3 * * * $UPDATE_CMD") | crontab - fi ``` ### Technical Analysis The installer modifies the user's crontab to run `git pull` every day at 03:07. This creates cross-session persistence and permits future content from the mutable `main` or `master` branch to become active without user review or approval. Although `git pull --ff-only` prevents non-fast-forward merges, it does not authenticate the semantic safety of new commits or restrict updates to audited versions. A compromised upstream repository can change `SKILL.md`, executable scripts, reference data, or other files in the installed directory. The declared Skill is a static customer-service knowledge package. A persistent operating-system scheduler is not necessary for its normal runtime behavior. ### Attack Path 1. A user runs the Unix installer. 2. The installer adds a daily cron entry without requiring a separate explicit opt-in. 3. At a later time, an attacker compromises the upstream repository or maintainer account. 4. The attacker commits malicious Skill instructions or executable content to `main` or `master`. 5. Cron runs the stored update command at 03:07. 6. Git retrieves and activates the attacker-controlled changes without a new installation review. 7. The modified Skill affects future Agent sessions or provides a staging point for additional malicious behavior. ### Impact Assessment The scheduled task persists across terminal sessions and system reboots under the user's account. It can repeatedly retrieve upstream changes and alter the installed Skill with the user's file permissions. T ...[truncated 236 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
install.ps1:42
Finding

Windows Installer Establishes Unattended Daily Code Updates Through Task Scheduler

Content
View full analysis
`$null; if (`$LASTEXITCODE -ne 0) { git pull --ff-only origin master 2>`$null }`"" -WorkingDirectory $SkillPath $Trigger = New-ScheduledTaskTrigger -Daily -At 03:07 Register-ScheduledTask -TaskName $TaskName -Action $Action -Trigger $Trigger -Description "奕辰垃圾袋Skill自动更新" | Out-Null } ``` ### Technical Analysis The installer registers a persistent Windows scheduled task that invokes PowerShell daily and retrieves changes from mutable upstream Git branches. Future updates are accepted without version pinning, signature verification, checksum verification, or interactive approval. Checking whether a task with the same name already exists prevents only duplicate registration. It does not constrain the content later retrieved by Git or validate that the upstream commit is trusted. A persistent Windows scheduled task is not required for the Skill's declared product-information and customer-service behavior. ### Attack Path 1. A user executes the PowerShell installer. 2. The installer creates `YichenTrashBagSkillUpdate` in Windows Task Scheduler. 3. An attacker later compromises the upstream repository or its maintainer account. 4. The attacker pushes malicious content to `main` or `master`. 5. At 03:07, Task Scheduler launches PowerShell under the task's configured security context. 6. The task pulls the malicious changes into the installed Skill directory. 7. The altered files remain available to future Agent sessions without additional user approval. ### Impact Assessment The task survives the inst ...[truncated 412 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
install.sh:38
Finding

Unix Installer Recursively Deletes an Existing Skill Directory Without Confirmation

Content
View full analysis
/dev/null || cp -r "$TMP_DIR/repo" "$SKILL_PATH" ``` ### Technical Analysis When the destination exists but is not treated as an existing Git installation, the installer recursively and forcibly deletes the entire destination without confirmation, backup, ownership validation, or canonical-path validation. `SKILL_PATH` is derived from `SKILLS_DIR`, which can be supplied through the environment. Although `SKILL_NAME` is fixed, a mistaken or maliciously prepared environment can direct the installer toward an unexpected existing directory. Even during normal use, all local modifications in a non-Git Skill directory are destroyed. ### Attack Path 1. The destination Skill directory already exists and contains local changes or unrelated files. 2. Alternatively, the installer is launched with an unexpected `SKILLS_DIR` environment value. 3. The installer detects the existing directory. 4. `rm -rf` deletes the directory recursively without requesting confirmation. 5. The downloaded repository content is copied into the now-empty location. 6. The prior contents are unavailable unless independently backed up. ### Impact Assessment The operation can cause irreversible loss of data accessible to the invoking user within the resolved destination directory. It does not directly grant new privileges to an attacker, but it creates avoidable integrity and availability risk. If executed under a privileged account with a dangerously configured destination, the deletion scope may include privileged files at that resolved path. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
install.ps1:28
Finding

Windows Installer Recursively Deletes an Existing Skill Directory Without Confirmation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (27)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash and PowerShell iex pattern is a classic command-chaining anti-pattern that converts untrusted network content directly into code execution with no inspection barrier. In this skill context, the install commands appear in a public-facing README for a customer-service skill, so routine users may copy/paste them without security scrutiny, greatly increasing the chance of compromise.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

bash
# macOS / Linux
curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash

# Windows(PowerShell)
powershell -c "irm https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.ps1 | iex"

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a customer-service skill focused on answering product and commerce-related user queries. However, the supplied code does not implement any customer-service logic, product handling, or query processing. Instead, it is purely an installation/update shell script that downloads code from GitHub, writes into the user's local skills directory, and persists a cron-based auto-update task. These are material behaviors not reflected in the declared purpose or permissions. While installation can be a supporting detail for distributing a skill, this code chunk itself has a different primary function and includes undeclared system-modifying capabilities, especially cron persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents an end-user-facing e-commerce customer service skill for trash bags and related products. However, the supplied code is not implementing customer support logic, recommendation logic, pricing/shipping/after-sales handling, or any user-triggered conversational behavior. It is a test script whose primary purpose is to verify that the skill package contains required files and expected text patterns. This is a materially different primary purpose from the declared description, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

One-word triggers like '推荐', '价格', '优惠', '快递', '退', and '质量' are extremely collision-prone and likely to match normal conversation across many domains. In an agent environment, this can hijack routing, force irrelevant persona/instructions, and interfere with safer or more appropriate skills, increasing the risk of misclassification and unintended behavior.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Using curl ... | bash enables immediate execution of remote code without inspection, validation, or provenance checks. This is especially dangerous because the same installer already performs filesystem modification and persistence setup, so compromise of the source can directly lead to arbitrary code execution and durable host changes.

Content

Scanner excerpt · install.sh (reported line 6)May include surrounding context.

sh
# 奕辰垃圾袋(Yichen Trash Bag)Skill · 一键安装脚本
# ============================================================
# 用法(客户只需运行这一行):
#   curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash
# ============================================================

set -e

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes "垃圾袋" as a standalone activation keyword, which is a generic product term likely to appear in ordinary shopping conversations unrelated to this specific skill. The README does not provide limiting context, exclusion conditions, or negative examples to distinguish when the skill should activate versus when it should not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs users to execute remotely fetched scripts directly with bash and iex without any integrity verification, review step, or warning. This creates a direct path for arbitrary code execution if the upstream repository, network path, or referenced script is compromised, and README-driven copy/paste makes exploitation more likely.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad, everyday shopping terms such as '垃圾袋', '一次性用品', and related generic product words. This can cause the skill to activate outside its intended context, overriding other skills or injecting brand-specific sales behavior into unrelated conversations, which is a prompt-routing integrity issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill instructs the AI to act as a Chinese-language storefront客服 using prescribed Chinese phrasing such as “亲~” and “咱家,” but it does not state that users can choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy issue unless the locale limitation is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer forcefully deletes any existing skill directory and then installs replacement content, while also registering persistence, all without prompting the user or warning about these system modifications. This can cause data loss, overwrite local changes, and silently establish long-lived behavior that the user did not knowingly approve.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installer registers a persistent Windows scheduled task to run daily, which goes beyond a one-time skill installation and creates ongoing code execution on the host. For a simple e-commerce customer-service skill, this persistence is not clearly necessary and increases the attack surface because any future repository compromise or unintended update will be executed automatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script creates a daily auto-update mechanism that executes git pull from a remote repository without meaningful trust controls such as version pinning, signature verification, or user approval. This is dangerous because it turns the installed skill into a continuously changing codebase and allows upstream compromise to propagate automatically onto the user's system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The final instruction says the AI should be invoked with only the Chinese phrase "奕辰垃圾袋," indicating a fixed language requirement. This is a natural-language policy concern because the file does not offer alternative trigger wording or user opt-in for language/locale preference.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Deleting an existing installation directory without an explicit warning or confirmation is unsafe because users may lose local files, edits, or unrelated data if the path is misconfigured. In an installer distributed for one-line execution, this lack of informed consent materially raises operational risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer establishes a persistent daily cron job to pull and execute updated repository content over time, which is unrelated to the narrow stated purpose of an e-commerce customer-service skill. This creates an ongoing code delivery channel that can change behavior after installation without explicit user review, increasing the risk of later compromise if the repository is altered.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer silently modifies the user's crontab to create persistence and future network activity without explicit advance consent. This is dangerous because it alters system behavior beyond installation and can continue pulling changed code indefinitely, surprising users and weakening trust boundaries.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

Reading and conditionally modifying crontab to install a recurring update job creates persistence on the host. In the context of a simple retail support skill, this persistence is unnecessary and expands the attack surface by enabling unattended future code changes.

Content

Scanner excerpt · install.sh (reported line 49)May include surrounding context.

sh
# 配置自动更新(追加到 crontab,不重复添加)
UPDATE_CMD="cd $SKILL_PATH && git pull --ff-only origin main 2>/dev/null || git pull --ff-only origin master 2>/dev/null"
if ! crontab -l 2>/dev/null | grep -q "yichen-trash-bag"; then
    (crontab -l 2>/dev/null; echo "7 3 * * * $UPDATE_CMD") | crontab -
    echo "自动更新已配置(每天 3:07)"
fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The command writes a new cron entry that will repeatedly execute git pull, establishing durable execution over time. Persistent scheduled tasks are risky because they survive the initial install and can later fetch and run altered repository content without prompting the user.

Content

Scanner excerpt · install.sh (reported line 50)May include surrounding context.

sh
# 配置自动更新(追加到 crontab,不重复添加)
UPDATE_CMD="cd $SKILL_PATH && git pull --ff-only origin main 2>/dev/null || git pull --ff-only origin master 2>/dev/null"
if ! crontab -l 2>/dev/null | grep -q "yichen-trash-bag"; then
    (crontab -l 2>/dev/null; echo "7 3 * * * $UPDATE_CMD") | crontab -
    echo "自动更新已配置(每天 3:07)"
fi

External Script Fetching

Low
Category
Supply Chain
Confidence
96% confidence
Finding

Fetching an installation script from a remote URL at execution time means the code being run is whatever currently exists at that location, not a reviewed local artifact. If the GitHub account, repository, branch, or delivery chain is tampered with, users who follow the README command will run attacker-controlled code on their machines.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

bash
# macOS / Linux
curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash

# Windows(PowerShell)
powershell -c "irm https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.ps1 | iex"

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

L029 明确要求该 Skill 仅做咨询,不得作出越权处理承诺;但 L239-L243 的话术要求包含“我帮您记录反馈给店铺”,这暗示 Skill 会代为记录或转交反馈。由于本文件整体仅声明读取 references/ 文件进行回复,并未体现任何记录或转交机制,这种文案会让 Skill 的实际能力与文档承诺产生矛盾。

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The installer recommends fetching and executing a remote script directly from a raw URL, which bypasses normal review and integrity validation. This is risky because users are encouraged to trust whatever content is served at execution time, including any future repository changes or account compromise.

Content

Scanner excerpt · install.sh (reported line 6)May include surrounding context.

sh
# 奕辰垃圾袋(Yichen Trash Bag)Skill · 一键安装脚本
# ============================================================
# 用法(客户只需运行这一行):
#   curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash
# ============================================================

set -e

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script forcefully deletes an existing target directory when it is not a git checkout, which is a destructive system modification beyond simple skill installation. Although scoped to the skill path, it can cause data loss or overwrite local customizations without confirmation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line 56 instructs users to trigger the skill using the Chinese phrase “奕辰垃圾袋” only, which imposes a language-specific activation pattern. The file does not offer alternative language options or explain why the trigger must be limited to that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown content presents all product information exclusively in Chinese, which can constitute a language/locale policy violation under the stated rules when no user opt-in or justification is provided. There is no indication that this file is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.