Back to skill

Security audit

Skill Distiller

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Markdown-only guide for turning repeatable work into reusable processes, with no hidden execution, credential access, persistence, or destructive behavior found.

Before installing, be aware that the skill may be invoked for fairly broad process-design requests and some reference material mixes English and Chinese. It appears safe as an advisory workflow skill, but users may want clearer trigger wording or language cleanup for usability.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description is broad enough that the skill may activate for many loosely related requests, causing unintended invocation and workflow hijacking from more appropriate skills. In an agent system, ambiguous activation criteria can lead to wrong-task execution, unnecessary data collection, or user confusion even without explicit malicious content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The listed triggers are abstract concepts rather than clear user utterances, which increases the chance that normal conversation topics will spuriously match and invoke the skill. Because this skill is meta-process oriented and can reshape workflows, accidental invocation could displace safer or more relevant domain-specific handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Lines describing scenarios include Chinese text fragments ('切入', '干货'), and later process guidance also uses mixed-language terminology. Because the file does not state that it is intended for bilingual users or offer a language preference, it may impose a language/locale assumption without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The phrase 'Conflict → Clarify →干货 → Action' mixes English and Chinese within an instructional structure. Without an explicit bilingual or region-specific justification, this can conflict with language/locale expectations for users who may not understand both languages.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The phrase 'Short video hosts who get stuck on openings for more than 20 minutes each time' describes a general situation rather than a specific trigger or invocation condition. The document does not provide explicit trigger phrases, scope constraints, or negative examples to distinguish when the skill should activate versus when it should not.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains mixed-language phrases such as "Narrative is空洞", which imposes a specific language/locale style without any user opt-in or justification. The same pattern appears elsewhere in the file, indicating a natural-language policy issue rather than a formatting accident.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "Emotions影响 decisions" mixes English and Chinese in user-facing guidance, which can violate language/locale policy when no choice or justification is provided. Because this is instructional content, the language inconsistency may affect accessibility and policy compliance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The wording "Attention分散" mixes languages in a way that assumes readers can understand both, but the file does not offer language choice or explain a locale-specific purpose. That matches the policy category for language/locale violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "Brand/account positioning模糊" again mixes English and Chinese in natural-language content. Since the file does not explain that it is region-specific or allow users to choose language, this is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.