Back to skill

Security audit

Adversarial Review

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent adversarial code-review workflow, but it can be triggered broadly and then spawn agents, run commands, write reports, and edit code without a clear confirmation checkpoint.

Install only if you want an aggressive review workflow that may inspect much of the repository, run local commands, create docs/review reports, and make code/test changes. Before using it, set a narrow review scope and require explicit confirmation before remediation; avoid the provided install scripts unless you are comfortable installing mutable content from the publisher’s GitHub main branch.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是“技能本身的功能”——进行三方对抗式代码评审;但提供的代码块并没有实现任何代码审查、蓝军/第三方/中立裁定逻辑,也不分析用户代码。它的主要用途是安装和更新该技能:联网拉取仓库、复制文件到本地技能目录、备份已有安装并清理旧备份。这样的行为属于部署/安装能力,而非声明中的评审能力,且涉及未声明的远程网络访问和本地文件系统修改。因此描述与该代码块的实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向用户代码的多方对抗审查技能,其主要能力应是分析代码、提出缺陷、复核审查意见并给出裁定。但实际代码块是 verify-install.sh 安装验证脚本,目标对象是该 skill 自身的安装状态与规范完整性。它不会读取待审代码、不会执行蓝军/第三方/裁定流程,也没有任何与“发布前审查”“find bugs in my code”直接相关的实现。该代码的主用途与声明的技能用途明显不同,属于实质性不符。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- **对自己的产出同样取证**——第三方的 T 项总表也是六列、也受"未实测不得定高危"约束,落盘后同样跑一次 `check-report.mjs`。只查别人、不查自己的角色,最后一定会退化成"别人的证据要命令、我的证据靠我说"。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
- **对自己的产出同样取证**——第三方的 T 项总表也是六列、也受"未实测不得定高危"约束,落盘后同样跑一次 `check-report.mjs`。只查别人、不查自己的角色,最后一定会退化成"别人的证据要命令、我的证据靠我说"。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The script deletes paths with rm -rf based on names derived from directory listings rather than a safer, tightly validated path construction flow. Although the grep prefix filter reduces risk, an attacker who can place crafted entries in the backup root could potentially cause deletion of unexpected targets via symlink or unusual filesystem objects, and the installer runs with the user's privileges so accidental destructive cleanup is possible.

Content

Scanner excerpt · scripts/install.sh (reported line 66)May include surrounding context.

sh
if [ -n "$to_prune" ]; then
    while IFS= read -r stale; do
      [ -n "$stale" ] || continue
      rm -rf "${BACKUP_ROOT}/${stale}" && info "pruned old backup (kept newest ${KEEP_BACKUPS}): ${stale}"
    done <<< "$to_prune"
  fi
fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list is extremely broad, including generic phrases like 'critique this', 'find bugs in my code', and requests to improve code quality. In systems that auto-activate skills based on description matching, overly broad triggers can cause unintended activation, leading the agent to launch a heavy multi-agent review workflow, read more repository content than necessary, and invoke shell/tooling in contexts the user did not clearly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is written to operate in Chinese and strongly frames behavior in Chinese without indicating language negotiation. In an auto-routing environment, forcing a language without user opt-in can cause misunderstandings of findings, remediation, and safety-critical caveats, especially when the skill is used for security review where precision matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and the entire skill file are presented in Chinese, but there is no indication that the user can opt into this language or that the file is intended only for a Chinese-language or region-specific audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely written in Chinese and presents the skill example as the default experience, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is entirely written as a prompt template in Chinese and provides no indication that language choice is optional or user-selectable. Under the stated policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents natural-language invocation, so vague-trigger review applies. The examples include short phrases like '蓝军评审' and the statement '不需要记任何命令。skill 会自动接管流程', but do not provide exclusion conditions or clarify where these phrases are safe to say, which could cause unintended activation in ordinary conversation about code review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains extensive natural-language comments and user-facing output exclusively in Chinese, including the usage/error message printed to stderr. The policy only allows locale constraints when the skill offers user choice or clearly documents a justified region-specific limitation, which is not present here.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/check-report.mjs (reported line 118)May include surrounding context.

js
bash sh zsh dash pwsh powershell cmd bat fish
  cat head tail less more wc sort uniq cut tr sed awk grep egrep fgrep rg fd find xargs
  ls ll pwd cd echo printf test diff patch comm
  tar zip unzip gzip gunzip xz 7z rsync scp cp mv rm mkdir touch chmod chown ln
  curl wget httpie jq yq awk
  docker podman nerdctl kubectl helm kind minikube terraform pulumi ansible
  openssl ssh sftp nc dig nslookup ping traceroute

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Natural-language policy checks apply to all file types. The document is presented entirely in Chinese and introduces English only as '或英文', which implies a default language choice rather than offering an explicit user language preference or locale selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L090 instructs authors to include trigger phrases in both Chinese and English if the user base is bilingual, which imposes a language expectation in the skill guidance rather than offering a user choice. This is a natural-language locale policy concern because it prescribes language handling without explicit opt-in or alternative preference selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The final user-facing instruction tells the user to invoke the skill using one Chinese phrase or one English phrase, which embeds specific language choices directly in the script output. Because there is no user opt-in or configurable locale selection, this is a natural-language locale policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The final user-facing instruction includes a Chinese activation phrase alongside English, which imposes a specific language/locale in the skill's guidance without any opt-in or explanation. Under the policy rule, hard-coded language expectations in natural-language strings can be a locale-policy issue when no user choice is offered.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.