Back to skill

Security audit

Structured Dev

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed structured-development workflow that writes planning files in a project `.dev/` directory and only moves to implementation after user review.

Install this if you want a Chinese-first, document-heavy coding workflow that creates and updates `.dev/` planning files before implementation. Review the broad trigger phrases and expect project-local markdown files to be created or modified; no credential use, remote execution, or system persistence was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a high-level structured development process/workflow with stage enforcement and trigger phrases around research, planning, and implementation sequencing. The actual code does not implement or enforce such a pipeline. Instead, it is a simple progress-reporting script for a Markdown todo list in .dev/plan.md. This is a materially different primary purpose: reporting checklist completion versus orchestrating or enforcing a structured development lifecycle. There is no evidence of architecture review gating, workflow control, trigger handling, or multi-stage pipeline behavior in the supplied code.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill instructs the agent to create and modify files such as .dev/research.md and .dev/plan.md, which implies file read/write behavior, but it declares no explicit tool scope or permissions boundary. That mismatch can cause the skill to run with broader-than-expected filesystem access in hosts that rely on manifest-declared permissions, increasing the chance of unintended file modification or data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description, trigger phrases, and the overall instructional content are presented in Chinese as the default operating language, with no indication that the user may choose another language. This can violate language/locale policy where a skill should not impose a specific language unless the user opts in or the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad, natural-language phrases such as structured dev, 先调研再写代码, and research plan implement, which could activate the skill in ordinary development conversations without clear user intent. Over-broad activation raises the risk of the agent unexpectedly entering a file-writing workflow, creating .dev/ artifacts, or altering normal task handling when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents all prompt templates in Chinese and instructs their direct reuse, which effectively imposes a specific language on the skill's operation. There is no indication that users may choose another language or that the Chinese-only constraint is required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely written as Chinese-language guidance and does not indicate that the user may choose another language or locale. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script description, CLI help text, status messages, and generated markdown template labels are all hard-coded in Chinese. This can violate a language/locale policy when users are not given a choice of language or informed that the skill is Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and user-facing usage text are written only in Chinese, and later user-visible messages also assume Chinese output. This creates a language/locale constraint without any opt-in or documented justification, which matches the policy category for forced language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The argparse description and help text are presented only in Chinese, which means the skill enforces a specific language in its interface. Because no alternative language, opt-in, or scope limitation is provided, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.