Back to skill

Security audit

oss-voice

Security checks for vulnerabilities and agentic risk

Overview

This is an opinionated repository documentation and multilingual README style skill with disclosed, purpose-aligned behavior and no evidence of hidden execution or data exfiltration.

Before installing, be aware that this skill may encourage synchronized edits across multilingual README/docs files and may apply strong defaults for new repository language and naming. That is appropriate for documentation workflows, but users should explicitly specify target files, languages, and whether counterpart files should be updated when those choices matter.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises a long trigger list containing broad terms such as '文档整理', '国际化', and 'i18n', which can cause the router to invoke this skill for generic documentation or localization requests outside its intended scope. In an agent system, over-broad invocation increases the chance of unintended file modifications, policy conflicts, or routing away from a more appropriate and safer specialized skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill hard-codes language selection based on repository context ('目标文件现有语言 = 写作语言' and mandatory dual-file updates) without requiring an explicit user confirmation. That can override user intent, cause edits in additional files the user did not ask to touch, and create unauthorized multilingual changes in workflows where language choice is sensitive.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The new-repository rules prescribe language and naming conventions, including an English-default path for new repos, as a forced policy rather than an opt-in recommendation. In scaffold or repo-initialization scenarios, this can silently shape project artifacts and file layout contrary to stakeholder requirements, causing governance and localization mistakes that propagate across the repository.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.