Back to skill

Security audit

电脑清理大师

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed duplicate-file scanner with deletion guidance, but its bundled code only scans user-specified directories and writes reports.

Install only if you are comfortable letting the agent scan directories you choose. Review the report before deleting anything, prefer backup-or-move workflows first, and avoid system directories or broad home-directory scans unless you explicitly intend that scope.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description explicitly advertises '自动删除、手动确认、备份后删除' capabilities but does not pair them with a clear warning about irreversible data loss, false-positive duplicate detection, or the need for explicit user confirmation before deletion. In a duplicate-file-cleaning context, this omission is safety-relevant because users may trust the skill to remove files automatically and underestimate the risk of deleting important data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to scan directories, generate reports, and assist with deletion, which clearly implies file read and file write capabilities, yet it declares no explicit tool scope or permissions boundary. This increases the chance of overbroad filesystem access or unintended use of more powerful tools than necessary, especially because the workflow includes processing user-supplied paths and generating deletion scripts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L03 的技能描述全文使用中文,未说明是否仅面向中文用户,也未提供语言/locale 选择机制。根据规则,若技能在自然语言层面强制特定语言而没有用户选择或合理限定,属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad and based on common phrases like cleaning disk space or organizing photos, which could cause the skill to activate in routine conversations where the user did not intend filesystem scanning or deletion assistance. In this context, accidental invocation is more dangerous because the skill handles local file enumeration and can lead to report generation or follow-on destructive actions such as deletion script creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes broad use cases like cleaning files, freeing disk space, and organizing photo libraries across major desktop operating systems. This can cause the skill to be invoked for generic file-management requests beyond strict duplicate detection, increasing the chance of unnecessary filesystem scanning or cleanup suggestions in contexts where the user did not explicitly request duplicate-file analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language text that forces a specific language for the skill's description and interaction. Under the policy, language constraints should be optional or clearly justified as region-specific, but this file provides no opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This requirements file is entirely written in Chinese, including headings and usage-relevant notes, with no indication that another language is supported or that the skill is intentionally limited to a Chinese-speaking context. That creates a natural-language locale policy concern because the file imposes a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.