Back to skill

Security audit

Chu Hui

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a simple local optimizer and text-filter helper with no evidence of persistence, exfiltration, destructive behavior, or privilege escalation.

Install only if Chinese-language output is acceptable. Treat the optimization and tuning results as advisory unless you separately confirm any other skills it invokes before allowing real memory, workspace, or configuration changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill advertises environment optimization, memory cleanup, and parameter tuning actions that could affect system state, performance, or data retention, but it provides no safeguards, scope limits, rollback guidance, or operator warnings. In an agent context, vague optimization semantics can lead to overbroad or unsafe changes being applied to memory, CPU, network, or configuration surfaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code's natural-language strings, comments, labels, and output are consistently presented only in Chinese, including the CLI usage context and user-facing result fields. The file does not offer any language selection or document a justified region-specific constraint, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

At L066, the inline comment states '太激进,注释掉' ('too aggressive, commented out'), which indicates the pattern should not be active. However, the regex object remains in the active patterns array, so the documented intent contradicts the implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language policy violations apply to all file types, including markdown. The content appears to force a specific language for skill use/documentation without user opt-in or a documented justification for being Chinese-only, which can conflict with language/locale choice policies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.