Back to skill

Security audit

技能选择器

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only skill helps choose among installed skills and does not show hidden execution, persistence, exfiltration, or destructive behavior.

Install only if you are comfortable with a Chinese-language assistant that may activate on broad skill-selection phrases and inspect installed skill descriptions to recommend another skill. Review the recommendation before choosing a skill to load.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad natural-language phrases such as “该用什么” and “帮我选技能”, which are likely to appear in normal conversation and can cause accidental invocation. In this skill, unintended activation is more concerning because the skill can scan installed skills and route the user into another skill, creating confusing control flow and increasing the chance of inappropriate skill handoff.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill unconditionally forces Chinese output regardless of the user’s language preference or session context. This can degrade usability, cause misunderstandings, and in multilingual environments may result in mis-selection of skills or incorrect confirmation of the user’s intent, though it is not a direct code-execution or data-exfiltration issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese throughout the headings and descriptions, which can constitute a language/locale policy issue when no user opt-in or justified region-specific scope is provided. The content does not state that the skill is intended only for Chinese-speaking users or offer an alternative language choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.