Back to skill

Security audit

m

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broad command cheat sheet that exposes destructive file, package, and service-management actions under a one-letter trigger without enough guardrails.

Install only if you want a broad administrative shortcut and are comfortable reviewing every generated command before it runs. Treat package installs, removals, upgrades, service changes, recursive deletion, rsync --delete, database restore, and remote Git deletion as manual-confirmation actions; do not let an agent execute them automatically from vague requests.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:80
Finding

Unpinned Third-Party Package Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 80-94
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: Medium

Complete Code Snippet

bash
npm install express            # Install package
npm uninstall lodash           # Uninstall package
npm update                     # Update all packages
npm outdated                   # Check outdated packages
npm audit fix                  # Fix vulnerabilities
npm ci                         # Install from package-lock in CI

pip install django             # Install package
pip uninstall numpy            # Uninstall package
pip list --outdated            # List outdated packages
pip freeze > requirements.txt # Export dependencies
pip install -r requirements.txt  # Install dependencies in bulk
pip check                      # Check dependency conflicts

Technical Analysis

The Skill recommends installing third-party npm and Python packages without requiring exact version pins, integrity hashes, a reviewed lockfile, or a restricted package registry. Commands such as npm install express and pip install django resolve mutable package versions and transitive dependencies at execution time. The security properties of the installed code can therefore differ from those present when the Skill was reviewed.

The requirements-file command is also unsafe when the referenced file is untrusted or lacks exact versions and hashes. A malicious or compromised package may execute installation hooks, build backends, or other package-controlled code. The npm update and npm audit fix examples can additionally change dependency versions beyond those already reviewed.

These commands are documentation examples and are not executed automatically by the project. Exploitation therefore requires an Agent or user to follow the instructions in an environment where a malicious dependency, registry response, lockfile, or requirement ...[truncated 1466 chars]

Remediation
View remediation

Remediation Suggestions

  • Require exact package versions rather than unconstrained package names.
  • For npm, prefer npm ci with a reviewed and committed lockfile instead of npm install or broad npm update operations.
  • For Python, use a reviewed requirements file containing exact versions and verified hashes, then install with:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  • Configure trusted registries explicitly and reject unexpected package indexes or registry overrides.
  • Review transitive dependencies, package ownership, release history, and installation scripts before installation.
  • Run package managers as an unprivileged user in an isolated virtual environment or container.
  • Require explicit user confirmation before installing or updating dependencies, especially in CI or production environments.
  • Avoid automated broad fixes such as npm audit fix unless the resulting dependency changes have been reviewed and tested.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (32)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A single-letter trigger m combined with a very broad scope makes accidental invocation highly likely. Because the skill includes destructive file moves, package changes, service control, and data migration, an unintended activation could lead to system-altering actions in response to ordinary conversation.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

rm -r source/ is a destructive deletion command presented immediately after a copy/sync example, with only a brief comment to confirm first. In an agent skill, recursive deletion is dangerous because misresolved paths, variable expansion mistakes, or user misunderstanding can permanently remove large amounts of data.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

mv 原地操作,无法跨设备

跨设备需要用cp+rm,或rsync

rsync -avh source/ /mnt/other_disk/backup/ rm -r source/ # 确认后再删

text

---

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section presents destructive and system-altering commands such as package install/remove/purge, upgrades, service start/stop/restart, and startup persistence changes, but without prominent safety gates. In an agent skill, offering these commands as routine examples normalizes risky actions and can cause privilege use or service disruption without adequate user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document presents the skill title and explanatory instructions primarily in Chinese, with only limited English examples, and does not state that language is selectable by the user. This can violate language or locale policy where skills should not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation examples are broad everyday requests such as moving files, reorganizing projects, and managing software/services, without boundaries or exclusions. This increases the chance that the agent routes normal user requests into a powerful skill that can rename, delete, install, uninstall, or reconfigure critical resources.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
92% confidence
Finding

sudo apt update is a privileged system command. In a broad, easily triggered skill, even routine privileged package-management examples are dangerous because they encourage elevation in contexts where the user may not expect system-wide changes.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

apt (Ubuntu/Debian)

bash
sudo apt update               # 更新索引
sudo apt install nginx        # 安装
sudo apt remove nginx         # 卸载(保留配置)
sudo apt purge nginx          # 完全卸载(含配置)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

sudo apt install nginx performs system-wide software installation with elevated privileges. Within this skill's broad routing surface, that can materially alter the host, introduce network-facing services, and expand attack surface if triggered unintentionally.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

apt (Ubuntu/Debian)

bash
sudo apt update               # 更新索引
sudo apt install nginx        # 安装
sudo apt remove nginx         # 卸载(保留配置)
sudo apt purge nginx          # 完全卸载(含配置)
sudo apt upgrade              # 升级所有

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

sudo apt remove nginx removes software at the system level and may disrupt dependent workflows or services. In an ambiguously invoked skill, this is dangerous because a normal 'manage software' request could be interpreted as a destructive privileged action.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

bash
sudo apt update               # 更新索引
sudo apt install nginx        # 安装
sudo apt remove nginx         # 卸载(保留配置)
sudo apt purge nginx          # 完全卸载(含配置)
sudo apt upgrade              # 升级所有
sudo apt autoremove           # 清理无用依赖

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

sudo apt purge nginx is more destructive than a simple remove because it also deletes configuration. Exposing it as a standard example without strong warnings increases the risk of permanent service misconfiguration or data loss.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

sudo apt update # 更新索引 sudo apt install nginx # 安装 sudo apt remove nginx # 卸载(保留配置) sudo apt purge nginx # 完全卸载(含配置) sudo apt upgrade # 升级所有 sudo apt autoremove # 清理无用依赖

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

sudo apt upgrade changes many system packages at once with elevated privileges. While common in administration, it can break compatibility or unexpectedly restart services if surfaced by a broadly scoped skill.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

sudo apt install nginx # 安装 sudo apt remove nginx # 卸载(保留配置) sudo apt purge nginx # 完全卸载(含配置) sudo apt upgrade # 升级所有 sudo apt autoremove # 清理无用依赖

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

sudo apt autoremove can remove packages automatically, which may surprise users and affect installed tooling. In this skill context, the issue is not the command itself but its inclusion without guardrails in a highly permissive skill.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

sudo apt remove nginx # 卸载(保留配置) sudo apt purge nginx # 完全卸载(含配置) sudo apt upgrade # 升级所有 sudo apt autoremove # 清理无用依赖

text

**yum/dnf (CentOS/RHEL/Fedora)**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

sudo dnf install nodejs installs software with root privileges and changes the host state. In a skill that may trigger on vague requests, privileged installation guidance creates a real risk of unintended system modification.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

yum/dnf (CentOS/RHEL/Fedora)

bash
sudo dnf install nodejs       # 安装
sudo dnf remove mysql-server  # 卸载
sudo dnf upgrade              # 升级
sudo dnf autoremove           # 清理

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

sudo dnf remove mysql-server can disable or break a database service and remove critical software. Presented without safety checks, this can lead to outage or data-access disruption if invoked accidentally.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

yum/dnf (CentOS/RHEL/Fedora)

bash
sudo dnf install nodejs       # 安装
sudo dnf remove mysql-server  # 卸载
sudo dnf upgrade              # 升级
sudo dnf autoremove           # 清理

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

sudo dnf upgrade performs broad elevated changes across the system. The danger here comes from exposing mass-change admin actions in a skill with ambiguous activation and mixed-use scope.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

bash
sudo dnf install nodejs       # 安装
sudo dnf remove mysql-server  # 卸载
sudo dnf upgrade              # 升级
sudo dnf autoremove           # 清理

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

sudo dnf autoremove can delete packages and dependencies automatically with root privileges. Without warnings or review steps, it can remove components the user did not intend to affect.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

sudo dnf install nodejs # 安装 sudo dnf remove mysql-server # 卸载 sudo dnf upgrade # 升级 sudo dnf autoremove # 清理

text

**brew (macOS)**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

sudo systemctl start nginx starts a system service with elevated privileges and may expose network functionality. In a broad skill, service-control commands are risky because accidental use can alter system behavior or expand exposure.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

systemd (Linux)

bash
sudo systemctl start nginx              # 启动
sudo systemctl stop nginx               # 停止
sudo systemctl restart nginx            # 重启
sudo systemctl reload nginx             # 重载配置(不中断)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

sudo systemctl stop nginx can cause immediate service interruption. In this context the lack of confirmation or impact warning makes the example operationally dangerous.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

systemd (Linux)

bash
sudo systemctl start nginx              # 启动
sudo systemctl stop nginx               # 停止
sudo systemctl restart nginx            # 重启
sudo systemctl reload nginx             # 重载配置(不中断)
sudo systemctl enable nginx             # 开机自启

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

sudo systemctl restart nginx interrupts and reinitializes a running service. If routed from an ambiguous request, it can create avoidable downtime or apply broken configuration unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

bash
sudo systemctl start nginx              # 启动
sudo systemctl stop nginx               # 停止
sudo systemctl restart nginx            # 重启
sudo systemctl reload nginx             # 重载配置(不中断)
sudo systemctl enable nginx             # 开机自启
sudo systemctl disable nginx            # 禁用自启

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
92% confidence
Finding

sudo systemctl reload nginx is less disruptive than restart but still changes service state under privilege. Without guardrails, even reload actions can apply faulty configuration or change production behavior unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
sudo systemctl start nginx              # 启动
sudo systemctl stop nginx               # 停止
sudo systemctl restart nginx            # 重启
sudo systemctl reload nginx             # 重载配置(不中断)
sudo systemctl enable nginx             # 开机自启
sudo systemctl disable nginx            # 禁用自启
sudo systemctl status nginx             # 查看状态

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

sudo systemctl enable nginx persists service startup across reboots, creating a lasting host configuration change. In an easily triggered skill, persistence-changing commands are especially dangerous because they alter future system behavior beyond the current session.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
sudo systemctl stop nginx               # 停止
sudo systemctl restart nginx            # 重启
sudo systemctl reload nginx             # 重载配置(不中断)
sudo systemctl enable nginx             # 开机自启
sudo systemctl disable nginx            # 禁用自启
sudo systemctl status nginx             # 查看状态
sudo systemctl is-active nginx          # 是否运行

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

systemctl enable nginx configures the service to start automatically, which is a persistence mechanism. In a mixed-purpose skill with weak trigger specificity, exposing persistence changes increases the risk of unintended or unauthorized long-term system modification.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
sudo systemctl stop nginx               # 停止
sudo systemctl restart nginx            # 重启
sudo systemctl reload nginx             # 重载配置(不中断)
sudo systemctl enable nginx             # 开机自启
sudo systemctl disable nginx            # 禁用自启
sudo systemctl status nginx             # 查看状态
sudo systemctl is-active nginx          # 是否运行

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

sudo systemctl disable nginx changes boot persistence and can prevent expected service startup later. The risk is operational disruption caused by a powerful admin command being accessible via an overbroad skill.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
sudo systemctl restart nginx            # 重启
sudo systemctl reload nginx             # 重载配置(不中断)
sudo systemctl enable nginx             # 开机自启
sudo systemctl disable nginx            # 禁用自启
sudo systemctl status nginx             # 查看状态
sudo systemctl is-active nginx          # 是否运行
sudo systemctl is-enabled nginx         # 是否启用

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

sudo systemctl reload nginx # 重载配置(不中断) sudo systemctl enable nginx # 开机自启 sudo systemctl disable nginx # 禁用自启 sudo systemctl status nginx # 查看状态 sudo systemctl is-active nginx # 是否运行 sudo systemctl is-enabled nginx # 是否启用

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

sudo systemctl reload nginx # 重载配置(不中断) sudo systemctl enable nginx # 开机自启 sudo systemctl disable nginx # 禁用自启 sudo systemctl status nginx # 查看状态 sudo systemctl is-active nginx # 是否运行 sudo systemctl is-enabled nginx # 是否启用

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

sudo systemctl reload nginx # 重载配置(不中断) sudo systemctl enable nginx # 开机自启 sudo systemctl disable nginx # 禁用自启 sudo systemctl status nginx # 查看状态 sudo systemctl is-active nginx # 是否运行 sudo systemctl is-enabled nginx # 是否启用

text

Static analysis

No suspicious patterns detected.