Back to skill

Security audit

amis-ui

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese-language amis UI schema helper with templates and a local validator; the reviewed risky-looking items are disclosed and aligned with that purpose.

Installers should treat this as a Chinese-language amis template and validation helper. Before using generated schemas against real backends, review API paths, POST/PUT/DELETE actions, login persistence, and any form data submission behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 81)May include surrounding context.

ls ~/.claude/skills/amis-json-skills/templates/

读取模板

cat ~/.claude/skills/amis-json-skills/templates/basic-crud.json

text

#### 方式三:对话中触发

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description presents the skill as a schema-generation expert that produces AMIS configurations based on business intent and supports advanced interactive behaviors. However, the supplied code chunk is a validation/analysis utility: it contains regex-based pattern libraries for identifying common schema mistakes and returning fixes or suggestions. Its main purpose is linting or reviewing existing schema-like content, not generating new AMIS JSON schemas. While some suggestions touch on mobile adaptation and component configuration, these are narrow support checks and do not match the declared primary capability of end-to-end schema generation with complex interactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description emphasizes schema generation expertise: understanding requirements and producing correct, interactive amis configurations. The supplied code does not generate schemas at all. Its primary function is validation of an already-supplied schema, with rule-based checks for page, form, CRUD, dialog, button, wizard, API, and event-action fields, then returning diagnostics. While this is related to amis, it is a materially different purpose from the declared generator role, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation guidance does not define when the skill should load versus when the agent should simply answer normally. In an agent environment, that ambiguity can cause opportunistic or accidental skill activation from common product-related requests, expanding the skill's reach beyond what the user explicitly asked for.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation guidance does not define when the skill should load versus when the agent should simply answer normally. In an agent environment, that ambiguity can cause opportunistic or accidental skill activation from common product-related requests, expanding the skill's reach beyond what the user explicitly asked for.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 52)May include surrounding context.

bash
# 查看可用模板
ls ~/.claude/skills/amis-json-skills/templates/

复制模板到你的项目:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 78)May include surrounding context.

bash
# 查看可用模板
ls ~/.claude/skills/amis-json-skills/templates/

复制模板到你的项目:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language descriptions and user-facing messages are written entirely in Chinese, starting with the header comment and continuing through the exported pattern messages and suggestions. This can violate a language/locale policy when a skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and validation messages entirely in Chinese, including the file description and many returned warning/error strings. Because the skill does not indicate that it is intentionally limited to Chinese-speaking users or provide any opt-in language selection, it conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language strings in the template header and UI labels are entirely in Chinese, which indicates the skill is designed to present a fixed language experience. There is no indication anywhere in the file that users can opt into this locale or select an alternative language, which can violate language-choice policy for generally applicable skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON template contains multiple user-facing strings in Chinese, including the title, card headers, and chart labels, but provides no indication that the language is configurable or user-selected. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON template contains user-facing labels and descriptions entirely in Chinese, such as the title, button label, and field labels. Under the policy rule for natural-language violations, forcing a specific language without opt-in or documented regional justification is a locale-policy issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file header describes the template as a '带过滤搜索的CRUD模板' for '需要条件搜索的数据列表', which frames it primarily as a filtered search/list view. However, the configuration includes write operations for creating, editing, and deleting records via POST, PUT, and DELETE APIs, expanding beyond a search/list template into full data mutation behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON manifest defines a login UI with a checkbox labeled '记住我' and text indicating the user can stay logged in for 30 days. For a markdown/manifest-style skill definition that affects authentication persistence and potentially device privacy, there is no accompanying warning or disclosure about the security implications of using this option on shared devices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest-like JSON defines a multi-step form that collects name and email and posts the data to /api/submit, but the template contains no visible notice, confirmation text, or warning about transmitting user data. Because the file itself describes behavior affecting user privacy, the lack of disclosure is a semantic safety issue under the missing user warnings rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON template uses Chinese-only natural-language labels and placeholders throughout the user interface, such as the title, field labels, and button text. Because the file does not offer a language choice or document that the skill is intentionally limited to a Chinese-speaking or region-specific context, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example '创建一个订单管理页面,需要有搜索筛选功能' is another broad natural-language trigger with no scope limits. Although lower risk than the earlier section, it reinforces a pattern where ordinary requests may silently activate the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The Antigravity runtime example combines explicit mention syntax with a common request phrase but does not state whether the mention is mandatory. That inconsistency can confuse implementers and increase the chance of accidental trigger behavior in MCP-integrated environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file documents supported methods including DELETE and provides a form submission example that posts data and redirects, but it does not include any warning that generated schemas may modify backend data or trigger irreversible actions. For markdown files, the skill description should disclose behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON template uses Chinese titles, labels, placeholders, and confirmation text throughout, which imposes a specific language on users without any visible opt-in or alternative locale handling. The policy for natural-language issues applies to all file types, including config/templates like this one.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Multiple visible strings, including the title, labels, and placeholders, are fixed in Chinese. This can violate language/locale policy when a skill forces a specific language without explicit user opt-in or documentation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.