Back to skill

Security audit

Qjzd Nav Cli Content

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward QJZD Nav CLI reference for managing links, categories, and tags, with expected but potentially destructive delete commands.

Install only if you intend agents to manage QJZD Nav content through qjzd-nav. Treat delete and category reorganization commands as irreversible unless your deployment documents recovery; list objects first, confirm IDs, and use backups or a non-production environment for bulk changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents direct deletion commands for links without any warning about destructive effects, recovery limitations, or the need to verify the target ID before execution. In an agent skill context, this increases the chance of accidental data loss because an automated or inattentive operator may execute the example as-is against production content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The category deletion section is more dangerous than a simple object delete because it can trigger broader content changes, including moving links to parent/default locations when using mode options. Without a clear warning, users or agents may cause unintended reorganization or loss of expected information architecture in addition to deleting the category itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The tag deletion example omits any warning that removing a tag can affect classification, automation, filtering, and user navigation behavior across linked content. In a content-management CLI skill, that omission makes accidental destructive changes more likely, especially when an agent may follow concise examples directly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.