Back to skill

Security audit

Tun Zei

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small diagnostic and cleanup-helper package with limited local reads and no evidence of deletion, exfiltration, persistence, or hidden execution.

Review the cleanup wording before relying on this skill: it advertises broad cleanup targets but the current script appears to simulate removal rather than delete anything. Users who expect real cleanup should verify behavior, and users who only want diagnostics should keep it to health and fix-suggestion use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises operational capabilities such as cleanup, health checks, and error repair, and the analyzer detected environment access capability, but the manifest does not declare any explicit tool scope or permissions boundary. This creates an implicit trust problem: an agent may invoke broader tools than intended, increasing the risk of unauthorized environment inspection or destructive actions during self-healing flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cleanup feature explicitly supports targets like temp, cache, logs, and all, and reports removed files and freed space, but it provides no warning, confirmation requirement, or safety constraints for destructive operations. In a self-healing or automated repair context, this could lead to irreversible deletion of useful logs, forensic evidence, or important data if triggered broadly or incorrectly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file uses Chinese for the title, comments, diagnostic messages, and CLI usage/help output, with no indication that the skill is intended only for Chinese-speaking users or that another language is available. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring at L43-L45 labels this function as "清理冗余" (cleanup redundant data), which implies an actual cleanup action. However, the implementation only reads the temp directory, counts candidate files, and returns simulated values for filesRemoved and freedSpace; no file deletion call such as fs.unlinkSync is performed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language interface and operational descriptions are entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.