Back to skill

Security audit

零依赖图标生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent local PNG icon generator; its only notable risks are broad activation wording, Chinese-only guidance, and optional marketplace-upload notes that users should read before publishing.

Install this if you want a local, no-dependency Python tool for simple generated PNG icons. Review the Chinese documentation and be aware that the marketplace-upload section is guidance only; publishing or uploading icons would be a separate user-directed action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description says to use this skill when the user asks things like "给工具/技能/应用生成图标" and especially "换个 icon" and "icon 生成器". These phrases are broad and conversational, and the file does not provide limiting context or negative examples to distinguish when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file contains all user-facing guidance in Chinese, and there is no indication that the skill is region-specific or that users may choose another language. Under the language/locale policy rule, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a zero-dependency local PNG icon generator, but this section instructs users on a separate platform publishing/upload flow, including specific API endpoints and payload handling. That capability is not needed to generate icons themselves and is unjustified by the skill's declared purpose as an offline icon generator.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.