Back to skill

Security audit

Antique

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plain Markdown skill with no executable payload, but its antique-collecting description does not match its location and venue-discovery instructions.

Review this skill carefully before installing. It does not appear to contain code or persistence, but its public purpose says antique appraisal while its actual instructions guide an agent toward location-based venue discovery, queueing, parking, and navigation behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata says it provides antique appraisal knowledge and online鉴定, but the body describes a different capability: location-based venue discovery with queue status, parking, navigation, and social heat. This mismatch can cause the agent/router to invoke the skill for unrelated user queries and expose users to deceptive or unexpected behavior, especially because the content resembles another domain entirely rather than a minor documentation error.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example invocations use very broad placeholders like '具体场景任务' and '核心功能', which can match many generic user requests. In an agent-routing system, this increases the chance of accidental or opportunistic triggering for unrelated prompts, causing misrouting, low-quality responses, or abuse of the skill as a catch-all entry point.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content is entirely in Chinese and presents the skill as operating in that language, but it does not indicate that Chinese is optional or that the skill is intentionally limited to a Chinese-speaking or China-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.