Back to skill

Security audit

Roundtable

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly coherent roundtable-analysis tool, but it stores sensitive discussion content and imported role prompts persistently in ways users should review before installing.

Review this before installing if you will discuss private, regulated, or business-sensitive topics. Prefer a project-scoped, pinned install; avoid global installation unless you trust the source. Do not import shared role files unless you inspect them for prompt-injection instructions. Treat memory/ archives as sensitive plaintext and either disable/avoid archiving, add memory/*.md to .gitignore, or delete archives after use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
tools/distill-character.md:92
Finding

Persistent Prompt Injection Through Untrusted External Role Imports

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:7
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
.gitignore:10
Finding

Plaintext Persistence of Sensitive User Context in Git-Trackable Archives

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (48)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all user-facing instructions in this README are presented exclusively in Chinese, including installation and usage guidance. For a general-purpose skill, this constitutes a language/locale policy concern because it does not offer users an explicit language option or explain why the skill is limited to Chinese.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx skills add lmf112358/table-skills without pinning an exact package version. That means installation behavior can change over time or be influenced by a compromised upstream package, tag move, or malicious newly published dependency, creating a supply-chain risk at install time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This global installation example again uses an unpinned npx skills add flow. A user following the README may fetch and execute whatever current package state resolves at that moment, which increases exposure to dependency hijacking or malicious upstream changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Specifying --agent claude-code does not reduce the core issue: the command still relies on an unpinned package resolution path. If the referenced package or dependency chain is compromised, users may execute attacker-controlled code during skill installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The call-to-action repeats the same unpinned npx skills add installation pattern, encouraging broad user execution of a floating upstream package. Repetition in prominent README sections increases the likelihood of unsafe copy-paste adoption and therefore raises practical exploitation risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Broad triggers like '帮我做个决策', '从多个角度分析', and '有什么风险' are likely to match ordinary conversation and cause the skill to activate unexpectedly. Unintended activation can expose user content to extra processing, invoke persistence behaviors, and alter assistant behavior without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill stores discussion archives but does not clearly warn users in the main description or trigger surface that their discussions may be written to disk. This undermines informed consent and increases privacy/compliance risk, particularly because roundtable topics may include sensitive business, personal, or strategic information.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The task decorator and archive design explicitly preserve user-provided personal information and discussion context in persistent memory files. Persisting personal/contextual data across sessions increases the risk of privacy leakage, unintended reuse, profiling, and access by unrelated workflows, making the skill materially more dangerous than a transient analysis tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill fixes its instructions and interaction style to a single language, Chinese, across the whole file. Under the policy, language-specific behavior should either provide user opt-in/choice or clearly justify the locale constraint, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill definition is written as a Chinese-language expert persona and provides no indication that users may interact in another language or choose a locale. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill definition is written in Chinese and presents no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale limitation is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill specification is written as prescriptive behavior in Chinese, including mandatory interaction patterns such as "必须追问" and "必须强制拉回这个话题," but it provides no opt-in or alternative language handling. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire skill is written to operate in Chinese, including headings, guidance, and quoted response style, with no indication that the user may choose another language. This creates a natural-language locale constraint that is not presented as optional or justified as region-specific compliance content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is written entirely in Chinese and presents its instructions, style, and interaction patterns only in that language, with no indication that users may choose another language. This can violate a language/locale policy when a skill imposes one language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill is written to operate in Chinese, including its title, guidance, and quoted interaction style, with no indication that the user may choose another language. This can violate language/locale policy when a skill implicitly constrains responses to a single language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill is written as prescriptive role guidance in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to Chinese-speaking contexts. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown skill uses only Chinese natural-language instructions and headings, which can effectively force a specific language on users without opt-in. The policy allows locale constraints when they are explicitly justified, but this file does not state that it is intended only for Chinese-speaking users or offer an alternative language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire protocol is written as mandatory operating instructions in Chinese, and the file does not state that language selection is optional or limited to a China-specific context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The title and body instructions are entirely in Chinese and present the output protocol as fixed, which implies the skill enforces a specific language/locale. The file does not mention any user opt-in, language selection, or region-specific justification for this constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill definition is written as a Chinese-language role specification and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill is written as normative role instructions in Chinese and does not indicate that the user may choose another language or locale. Under the policy, language constraints should be opt-in or explicitly justified; here no such choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown skill defines its role and operating instructions exclusively in Chinese, and nowhere indicates that the user may choose another language or that the skill is intentionally limited to a Chinese-language context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.