Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md Before multi-step cloud writes, use `scripts/task-state.mjs` as described in
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s sensitive Onimi cloud actions are disclosed, user-directed, and scoped to creating, saving, publishing, and sharing Onimi Pages or Slides.
Install only if you intend to let Onimi handle private drafts, publishing, and sharing for Pages or Slides. Review the OAuth scopes in the browser, keep controlled-sharing links private, and use the dashboard to revoke access when you no longer need the integration.
Referenced artifact was not completely inspected
Before multi-step cloud writes, use `scripts/task-state.mjs` as described in
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Before multi-step cloud writes, use `scripts/task-state.mjs` as described in
[publish.md](references/publish.md). Retain exact mutation IDs and fixed references
for uncertain retries; reconcile actual server receipts before claiming success.
Private source, credentials and one-time access secrets stay outside the Skill and Git.
Validate the complete artifact and audience before publishing. Keep controlled-cloud
works private. Report only the saved/published revision and access that the server
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
editorial reading path, anchored evidence, and a print layout.
- Operational material such as runbooks, plans, and itineraries benefits from sequence, progress, and
locally persistent or clearly temporary check state.
- Comparison and calculation tools need explicit inputs, immediate results, sane defaults, and a clear
statement that sample figures are illustrative.
- Teaching and quiz pages need visible progress, reversible choices, keyboard-complete controls, and
feedback that explains the result.
Without declared permissions the skill's intent is opaque and cannot be validated.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
work name or link for an update, or confirmed project name and `public`, `unlisted`, or
`private` access for a new project. Explain that public projects are listed in Explore and open to
anyone, unlisted projects are open to anyone with the link, and private projects require owner/grant
access. An explicit controlled-sharing choice establishes private access, so explain it without asking
the user to confirm private a second time.
Updating keeps the same project, revisions, release history, visibility, grants and controlled data
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
work name or link for an update, or confirmed project name and `public`, `unlisted`, or
`private` access for a new project. Explain that public projects are listed in Explore and open to
anyone, unlisted projects are open to anyone with the link, and private projects require owner/grant
access. An explicit controlled-sharing choice establishes private access, so explain it without asking
the user to confirm private a second time.
Updating keeps the same project, revisions, release history, visibility, grants and controlled data
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
work name or link for an update, or confirmed project name and `public`, `unlisted`, or
`private` access for a new project. Explain that public projects are listed in Explore and open to
anyone, unlisted projects are open to anyone with the link, and private projects require owner/grant
access. An explicit controlled-sharing choice establishes private access, so explain it without asking
the user to confirm private a second time.
Updating keeps the same project, revisions, release history, visibility, grants and controlled data
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
original task. Report only observed stages, never a percentage. Verify with the least sensitive safe
read: call `onimi_get_connection` and compare its account and effective scopes. If an older deployed
service does not expose it, `onimi_list_projects` is a compatibility fallback and an empty list is
success. Do not read a private draft or create a project as a connection test. The connection tool's
`installedModules: "client-local-check-required"` means inspect the actual local Skill directory; never
infer installation from the server. If the user cancels, preserve the local artifact and these exact
continuation identifiers when present: `resourceType`, `resourceKey`, `resourceVersion`, `locale`, and
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Before any project or release write, establish the target intent from the whole conversation: update
one existing project, or create one new project. A generic request to publish does not mean create a
new project. Reuse an explicit earlier choice of target, project name or access; do not ask the user to
confirm the same choice again.
Inspect the actual discovered input schema before using a project selector. When that tool
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
that readback succeeds. A 409 means another save won; read and reconcile the new head. Never
change the body or expected revision while reusing an idempotency UUID.
For a small Slides source that the client can forward without truncation, `onimi_save_draft` is
also valid with the complete source, exact manifest, current revision and UUID. If saving returns
`INVALID_SOURCE`, inspect the actual source and manifest against the accepted schema; do not
silently drop resource provenance, create another project or claim that a local file is a saved
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
that readback succeeds. A 409 means another save won; read and reconcile the new head. Never
change the body or expected revision while reusing an idempotency UUID.
For a small Slides source that the client can forward without truncation, `onimi_save_draft` is
also valid with the complete source, exact manifest, current revision and UUID. If saving returns
`INVALID_SOURCE`, inspect the actual source and manifest against the accepted schema; do not
silently drop resource provenance, create another project or claim that a local file is a saved
The code throws unless locale is exactly "en" or "zh-CN", which enforces a narrow language/locale policy in code. This is a natural-language policy concern because the file does not offer user choice or document a region-specific justification for excluding other locales.
该文件全文以中文撰写,未见提供语言选择、用户 opt-in,或说明这是仅面向特定中文用户群体的区域化版本。根据规则,强制特定语言而无选择可能构成语言/区域策略问题。
The manifest defines only "zh-CN" and "en" under the locales section, which indicates the skill is constrained to specific languages. Under the policy criteria, forcing a specific language set without user opt-in or a documented regional justification can be a natural-language policy concern.
This manifest defines only zh-CN and en locale entries, which imposes a language constraint in the skill configuration. Under the policy, language or locale restrictions should either offer user choice or be clearly documented and justified as region-specific.
The code rejects any locale except "zh-CN" and "en" with an "Unsupported content locale" error. This is a natural-language locale restriction, and the file does not provide an opt-in mechanism or explain why the limitation is required.
No suspicious patterns detected.