Back to skill

Security audit

Problem Solving

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent problem-solving methodology skill with no executable payload, hidden behavior, credential handling, or destructive instructions.

Install this if you want the agent to use a more deliberate diagnostic workflow. Before allowing it to inspect logs, configuration, databases, session stores, write .learnings/ notes, or hand work to another coding agent, make sure those actions fit the specific task and permissions you intend to grant.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This README says the skill "activates automatically when appropriate" without clearly defining boundaries, and it includes broad example invocations like "帮我分析一下这个问题" that overlap with common everyday requests. That combination can cause unintended invocation because users are not given a precise trigger scope or exclusion criteria for automatic activation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 61)May include surrounding context.

md
## Anti-Patterns to Avoid

- **Guess-and-fix**: See symptom → change immediately
- **Surface fix**: Change bad value without asking why
- **Multi-change**: Change 3 things at once
- **Premature victory**: "Should be fixed" without verification

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
## Anti-Patterns to Avoid

- **Guess-and-fix**: See symptom → change immediately
- **Surface fix**: Change bad value without asking why
- **Multi-change**: Change 3 things at once
- **Premature victory**: "Should be fixed" without verification

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

md
- **Guess-and-fix**: See symptom → change immediately
- **Surface fix**: Change bad value without asking why
- **Multi-change**: Change 3 things at once
- **Premature victory**: "Should be fixed" without verification

## License

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description presents the skill's activation guidance in Chinese with embedded English phrases, which effectively assumes the user can understand Chinese. The policy for this audit flags language or locale constraints when a skill forces a specific language without user opt-in, and no alternative language option or opt-in is provided here.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
| One-end-only | Check only input or output | Trace full data flow |
| Surface fix | Change the bad value without asking why it's bad | Ask "why did it become this value?" |
| Multi-change | Change 3 things at once | One variable at a time |
| Premature victory | "Should be fixed now" without checking | Show evidence |
| No rollback | Forget to record original values | Backup before modify |

## Communication During Problem-Solving

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README uses a Chinese-language criterion ("你'd need to say '可能是...'" conceptually) and a Chinese trigger example in usage, but does not state that the skill is multilingual or that Chinese is optional. This can create an implicit language/locale constraint without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.