Back to skill

Security audit

Chou Fei

Security checks for vulnerabilities and agentic risk

Overview

This is a small Chinese-language resource and information-processing skill with mock fetching and local CPU-load reporting, and I found no hidden persistence, credential access, destructive behavior, or real network execution.

Install only if a Chinese-language interface is acceptable. Treat the fetch feature as currently simulated, and if extending it to real URL/API/file retrieval, add clear destination limits and user confirmation before sending sensitive content externally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes network-capable resource fetching but does not declare any tool scope, permissions, or allowed-tools boundaries. This can lead to overbroad runtime access, making it unclear what external systems the skill may contact and increasing the risk of unintended data exfiltration or SSRF-like behavior if integrated into an agent framework.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly offers external resource fetching but provides no warning that it may access network or external data sources. Users and orchestrators may invoke it without realizing prompts or attached context could be transmitted outward, creating privacy, consent, and data-handling risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s descriptive comments and CLI-visible output strings are written exclusively in Chinese, and there is no indication that the skill is intentionally limited to a Chinese-speaking context or that users can opt into another language. This can violate language/locale policy when a skill imposes a specific language without user choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function and doc comment label this capability as '资源获取' (resource fetching), and L023 states it is a simplified implementation, but the actual behavior at L024 only returns a mock string instead of fetching remote content. This is an active mismatch between the documented intent and what the code actually does.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level documentation frames the skill as '资源获取与信息摄取' (resource acquisition and information intake), and earlier functions align with fetching and summarizing content. The separate '算力调度' capability inspects host CPU state and returns compute-allocation decisions, which is not justified by the stated purpose available in the file documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s comments and, more importantly, its user-facing CLI/output strings are written exclusively in Chinese, indicating the skill forces a specific language/locale. The policy allows locale constraints only when user choice, opt-in, or clear justification is provided, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command usage text, progress messages, completion notices, and error messages shown to users are hardcoded in Chinese. This is a natural-language locale policy issue because the skill does not offer any language selection or disclose that it is intentionally restricted to Chinese users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language instructions and descriptions are presented in Chinese throughout the file, and the skill does not indicate that language selection is optional or region-specific. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command includes a fixed topic value in Chinese ("人工智能"), which suggests a language-specific behavior without any indication that the user can choose or opt into that locale. This can violate language/locale policy when a skill implicitly forces a specific language context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.