Back to skill

Security audit

blog-push

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local Hugo blog publishing helper, with disclosed file-writing behavior users should review before using on existing posts.

Before installing, confirm this is intended for your Hugo blog workflow. Use it on a version-controlled blog directory, check the generated destination path before publishing, and be aware that running it can overwrite an existing post and replace the source document's front matter in the generated output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents capabilities to read environment variables and read/write arbitrary local files, but it does not declare any explicit tool scope or permission boundaries. In an agent setting, this increases the chance the skill is invoked with broader file or env access than users expect, enabling unintended access to local content or writes outside the intended Hugo workspace.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match common publishing or blog-related requests, which can cause the skill to activate unexpectedly in contexts where the user did not intend file-moving or publication actions. Because the skill performs write operations and may overwrite content, overbroad activation materially raises the risk of unintended state-changing actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that existing target files will be overwritten, but the workflow does not prominently require an explicit confirmation immediately before publication. In a skill that writes into a content repository, silent or under-warned overwrite behavior can destroy existing posts or replace trusted content with unintended data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill notes that original front matter will be removed, but this destructive transformation is not highlighted as a major safety checkpoint in the publish flow. Removing front matter can strip important metadata such as draft status, aliases, taxonomy, canonical URLs, or custom rendering settings, causing publication mistakes or data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell example file presents all human-readable guidance in Chinese, including setup and invocation instructions. That creates a language-specific usability policy issue because the skill does not offer an alternative language or indicate that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a natural-language policy issue because the file presents its interface and documentation in one language only, which can exclude users who do not understand Chinese. The file does not offer an opt-in language choice or explain that the tool is intentionally limited to a Chinese-only audience or region.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script echoes raw environment variable values, including local filesystem paths, to stdout when --check-config is used. While this is not a severe issue in a local CLI context, it can leak sensitive workstation or repository layout information into terminal logs, CI logs, screenshots, or shared session transcripts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.