Back to skill

Security audit

Apollo Overview

Security checks for vulnerabilities and agentic risk

Overview

This is an overview-only coding methodology skill with no executable behavior, though its trigger wording and package slug should be reviewed for clarity.

Before installing, confirm you want a Chinese-language Apollo methodology overview that may activate on common coding requests. The publisher should fix the slug/name mismatch and narrow or clarify activation wording, but the inspected artifact does not show hidden code, credential access, persistence, or destructive actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are very broad (e.g. '开发新功能', '修bug', '写计划', '开始项目') and can match common user requests that do not explicitly ask for this specific skill. That creates prompt-scope creep: the skill may activate unexpectedly and steer unrelated conversations into its workflow, increasing the chance of unintended behavior or policy/workflow override in downstream agent orchestration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is written as a direct user-facing promise entirely in Chinese, with no indication that language selection is optional or tied to a region-specific use case. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest slug in _meta.json ('sysflow-overview') does not match the provided skill context name ('apollo-overview'), indicating an identity inconsistency. While this is not directly exploitable code execution, it can enable skill confusion, mislabeling, or accidental substitution during packaging, review, or deployment, which weakens trust and can hide the true provenance or purpose of the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.