Back to skill

Security audit

Feishu Multi Agent Manager

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Feishu multi-agent setup helper, but it stores secrets and writes persistent agent files with insufficient validation.

Review this before installing. Only use it in a trusted local OpenClaw environment, avoid custom agent IDs or names containing path characters, newlines, or instructions, treat Feishu App Secrets as sensitive, inspect generated openclaw.json and SOUL.md files before restart, and pin any npx-installed dependencies yourself.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/index.ts:489
Finding

Path Traversal Through Unvalidated Agent Identifiers

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
src/index.ts:538
Finding

Persistent Agent Instruction Injection Through Custom Agent Names

Content
View full analysis
Remediation
View remediation
64 || /[\r\n\u0000-\u001f\u007f]/.test(value) ) { throw new Error('Invalid Agent name'); } return value; } ``` 4. Require explicit administrator review and confirmation before writing any custom persona instructions. 5. Separate untrusted data from system instructions using a structured configuration field rather than prompt concatenation. 6. Add security tests using embedded headings, line breaks, tool-use instructions, Markdown fences, and oversized names. 7. Review the generated file before activating the Agent and provide a safe rollback procedure. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.ts:266
Finding

Secret-Bearing Configuration Backups Are Created Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
src/index.ts:638
Finding

Unpinned Third-Party Package Execution Recommended Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (48)

Known Vulnerable Dependency: handlebars==4.7.8 — 8 advisory(ies): CVE-2026-33916 (Handlebars.js has Prototype Pollution Leading to XSS through Partial Template In); CVE-2026-33937 (Handlebars.js has JavaScript Injection via AST Type Confusion); CVE-2026-33938 (Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @part) +5 more

Critical
Category
Supply Chain
Confidence
97% confidence
Finding

handlebars 4.7.8 has multiple serious advisories including prototype pollution and possible code or script injection through template compilation and partial handling. Even as a dev dependency, this is the most concerning finding because template engines are frequently fed semi-structured content in generators, test tooling, or scaffolding, and successful exploitation can lead to code execution or XSS-like impacts depending on usage.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README.md (reported line 88)May include surrounding context.

��会提供详细的创建教程 4. 配置凭证 - 逐个输入每个 Bot 的 App ID 和 App Secret 5. 验证并生成 - 自动验证凭证并生成配置 6. 重启生效 - 重启 OpenClaw 使配置生效

🎯 预设角色推荐

角色职责表情
main大总管 - 统筹全局、分配任务🎯
dev开发助理 - 代码开发、技术架构🧑‍💻
content内容助理 - 内容创作、文案撰写✍️
ops运营助理 - 用户增长、活动策划📈
law法务助理 - 合同审核、合规咨询📜
finance财务助理 - 账目统计、预算管理💰

🚀 快速开始

请告诉我:你想创建几个 Agent?

例如:

  • 3 个 - 我推荐:main(大总管)+ dev(开发)+ content(内容)
  • 6 个 - 完整团队:全部 6 个角色
  • 自定义 - 你自由选择角色

回复数字或"自定义",我们开始吧!😊

text

---

### 步骤 2:选择 Agent 数量

*

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个具备多项管理与自动化能力的技能,但给出的代码片段只是 src/types.d.ts 类型定义,用于描述运行时上下文接口。该代码没有展示任何与多 Agent 配置、批量操作、凭证校验、模板管理或备份相关的行为,也没有可执行逻辑。由于代码的实际作用与声明的主要目的存在实质性差异,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个功能较完整的“交互式多 Agent 管理/配置”技能,包含批量创建、凭证验证、角色模板、自动备份等能力。但给出的代码片段只是测试代码,不是功能实现代码;其实际行为仅包括:导入 main 并断言其存在,以及对飞书凭证格式做简单字符串规则测试(AppID 以 cli_ 开头、AppSecret 长度为 32)。因此,该代码片段与声明用途存在明显不一致,尤其在主要目的和能力范围上差异很大。

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
---
id: feishu-multi-agent-manager
owner_id: rfdiosuao
name: 飞书多 Agent 配置助手
description: 交互式引导配置多 Agent 系统,支持批量创建、凭证验证、角色模板、自动备份
version: 2.0.4
icon: "\U0001F916"
author: rfdiosuao
metadata:
  clawdbot:
    emoji: "\U0001F916"
    requires:
      bins: []
---

# 飞书多 Agent 配置助手 🤖

> 交互式引导配置多 Agent 系统,支持批量创建、凭证验证、角色模板

## ✨ 功能特性

### 1. 交互式配置向导
- 像聊天一样完成配置
- 询问创建几个 Agent(1-10)
- 提供预设角色推荐

### 2. 批量创建支持
- 一次性创建多个 Agent
- 自动验证每个�

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

brace-expansion 1.1.12 is flagged for multiple denial-of-service issues involving pathological brace patterns that can trigger excessive CPU or memory consumption. Even though it is transitive and primarily in tooling paths, a vulnerable parser in CI, linting, test discovery, or developer automation can still be crashed by crafted input.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==3.14.2 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

js-yaml 3.14.2 has reported CPU-exhaustion issues when parsing crafted YAML structures, including merge-key abuse and quadratic behavior. In this project it appears in dev tooling, which lowers exposure, but any workflow that parses untrusted YAML in automation or local setup could be vulnerable to denial of service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

brace-expansion 2.0.2 is separately present and affected by DoS conditions similar to the 1.x branch, allowing crafted expansion input to consume excessive resources or hang processes. Multiple vulnerable copies increase attack surface across tooling that performs glob or pattern expansion.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
92% confidence
Finding

browserslist 4.28.1 is flagged for crash/prototype-write and unbounded memory growth issues when handling untrusted stats or distinct query results. In this repository it is likely used by build/test tooling, so the main danger is denial of service or unsafe object mutation in tooling pipelines rather than direct production compromise.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: flatted==3.4.1 — 1 advisory(ies): CVE-2026-33228 (Prototype Pollution via parse() in NodeJS flatted)

High
Category
Supply Chain
Confidence
91% confidence
Finding

flatted 3.4.1 is reported vulnerable to prototype pollution during parse(), which can let crafted input modify object prototypes and potentially alter application or tooling behavior. Although this appears in development dependencies, prototype pollution can have broad downstream effects if untrusted serialized input is processed.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · src/index.ts (reported line 67)May include surrounding context.

ts
};
      compaction?: {
        mode: string;
      };
    };
    list: AgentConfig[];
  };
  channels: {
    feishu: {
      enabled: boolean;
      accounts: Record<string, FeishuAccount>;
    };
  };
  bindings: Array<{
    agentId: string;
    match: {
      channel: string;
      accountId: string;
      peer?: {
        kind: 'direct' | 'group';
        id: string;
      };
    };
  }>;
  tools: {
    agentToAgent: {
      enabled: boolean;
      allow: string[];
    };
  };
}

interface AgentTemplate {
  id: string;
  name: string;
  role: string;
  soulTemplate: string;
}

// ============================================================================
// 预定义的 Agent 角色模板
// ============================================================================

const AGENT_TEMPLATES: Record<string, AgentTemplate> = {
  main: {
    id: 'main',
    name: '大总管',
    role: '首席助理,专注于统筹全局、任务分配和跨 Agent 协调',
    soulTemplate: `# SOU

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs users to paste App ID and App Secret into the bot conversation for validation. In a chat-based agent environment, messages may be logged, retained, visible to operators, or exposed to other tools/plugins, so prompting users to submit secrets through chat creates a direct credential disclosure risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 601)May include surrounding context.

grep -i "error|fail" /home/node/.openclaw/run.log | tail -20

3. 测试飞书 API 连通性

curl -X POST "https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal"
-H "Content-Type: application/json"
-d '{"app_id":"cli_xxx","app_secret":"xxx"}'

text

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README makes conflicting security claims: it says each agent has isolated authentication, but the changelog earlier states that new agents automatically copy auth-profiles.json from an existing agent. That inconsistency can cause credential reuse or cross-agent trust leakage, undermining the documented isolation model and potentially exposing one agent's auth context to another.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly discusses credential handling and automatic backup/modification of configuration, but it does not present clear warnings about secret sensitivity, storage, disclosure risks, or filesystem changes. Users may provide AppSecret values or approve config edits without informed consent, increasing the chance of credential leakage or unintended persistent changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The trigger phrase '开始配置' is overly broad and not scoped to Feishu or multi-agent setup, so the skill could activate in unrelated conversations. In a skill that claims to handle credentials and configuration changes, accidental activation raises the risk of prompting for secrets or initiating config-altering flows without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill persists Feishu App ID/App Secret values into openclaw.json and also creates a backup file containing prior configuration state. For a skill presented as a configuration assistant, storing secrets on disk materially increases credential exposure risk through local compromise, backups, logs, or later accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill writes sensitive credentials and related configuration to disk during creation without an immediate user-facing warning on that execution path. In context, this is more dangerous because users are guided interactively to paste secrets into a trusted assistant, making silent persistence easy to overlook.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill expands the global agentToAgent.allow list for every created agent, broadening inter-agent communication privileges beyond simple Feishu bot setup. This increases lateral movement and abuse potential if any agent becomes compromised or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to install and run an external package via npx -y @larksuite/openclaw-lark without pinning a specific version. That creates a supply-chain risk because a future compromised or breaking release would be fetched automatically in a high-trust setup path for agent configuration.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · dist/index.js (reported line 800)May include surrounding context.

js
}
}
exports.default = main;
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi9zcmMvaW5kZXgudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IjtBQUFBOzs7Ozs7Ozs7OztHQVdHOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztBQWdqQkgsb0JBa1VDO0FBLzJCRCx1Q0FBeUI7QUFDekIsMkNBQTZCO0FBa0U3QiwrRUFBK0U7QUFDL0Usa0JBQWtCO0FBQ2xCLCtFQUErRTtBQUUvRSxNQUFNLGVBQWUsR0FBa0M7SUFDckQsSUFBSSxFQUFFO1FBQ0osRUFBRSxFQUFFLE1BQU07UUFDVixJQUFJLEVBQUUsS0FBSztRQUNYLElBQUksRUFBRSw4QkFBOEI7UUFDcEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBc0JqQjtLQUNFO0lBQ0QsR0FBRyxFQUFFO1FBQ0gsRUFBRSxFQUFFLEtBQUs7UUFDVCxJQUFJLEVBQUUsTUFBTTtRQUNaLElBQUksRUFBRSwwQkFBMEI7UUFDaEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQW9CakI7S0FDRTtJQUNELE9BQU8sRUFBRTtRQUNQLEVBQUUsRUFBRSxTQUFTO1FBQ2IsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsMEJBQTBCO1FBQ2hDLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxHQUFHLEVBQUU7UUFDSCxFQUFFLEVBQUUsS0FBSztRQUNULElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLDBCQUEwQjtRQUNoQyxZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQXFCakI7S0FDRTtJQUNELEdBQUcsRUFBRTtRQUNILEVBQUUsRUFBRSxLQUFLO1FBQ1QsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsd0JBQXdCO1FBQzlCLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxPQUFPLEVBQUU7UUFDUCxFQUFFLEVBQUUsU0FBUztRQUNiLElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLHdCQUF3QjtRQUM5QixZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBb0JqQjtLQUNFO0NBQ0YsQ0FBQztBQUVGLCtFQUErRTtBQUMvRSxPQUFPO0FBQ1AsK0VBQStFO0FBRS9FOztHQUVHO0FBQ0gsU0FBUyxrQkFBa0IsQ0FBQyxVQUFrQjtJQUM1QyxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxPQUFPLElBQUksQ0FBQyxLQUFLLENBQUMsT0FBTyxDQUFDLENBQUM7QUFDN0IsQ0FBQztBQUVEOztHQUVHO0FBQ0g7O0dBRUc7QUFDSCxTQUFTLFlBQVksQ0FBQyxVQUFrQjtJQUN0QyxNQUFNLFVBQVUsR0FBRyxHQUFHLFVBQVUsV0FBVyxJQUFJLENBQUMsR0FBRyxFQUFFLEVBQUUsQ0FBQztJQUN4RCxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxFQUFFLENBQUMsYUFBYSxDQUFDLFVBQVUsRUFBRSxPQUFPLEVBQUUsT0
...[truncated 27 chars]

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · dist/index.js (reported line 800)May include surrounding context.

js
}
}
exports.default = main;
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi9zcmMvaW5kZXgudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IjtBQUFBOzs7Ozs7Ozs7OztHQVdHOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztBQWdqQkgsb0JBa1VDO0FBLzJCRCx1Q0FBeUI7QUFDekIsMkNBQTZCO0FBa0U3QiwrRUFBK0U7QUFDL0Usa0JBQWtCO0FBQ2xCLCtFQUErRTtBQUUvRSxNQUFNLGVBQWUsR0FBa0M7SUFDckQsSUFBSSxFQUFFO1FBQ0osRUFBRSxFQUFFLE1BQU07UUFDVixJQUFJLEVBQUUsS0FBSztRQUNYLElBQUksRUFBRSw4QkFBOEI7UUFDcEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBc0JqQjtLQUNFO0lBQ0QsR0FBRyxFQUFFO1FBQ0gsRUFBRSxFQUFFLEtBQUs7UUFDVCxJQUFJLEVBQUUsTUFBTTtRQUNaLElBQUksRUFBRSwwQkFBMEI7UUFDaEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQW9CakI7S0FDRTtJQUNELE9BQU8sRUFBRTtRQUNQLEVBQUUsRUFBRSxTQUFTO1FBQ2IsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsMEJBQTBCO1FBQ2hDLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxHQUFHLEVBQUU7UUFDSCxFQUFFLEVBQUUsS0FBSztRQUNULElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLDBCQUEwQjtRQUNoQyxZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQXFCakI7S0FDRTtJQUNELEdBQUcsRUFBRTtRQUNILEVBQUUsRUFBRSxLQUFLO1FBQ1QsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsd0JBQXdCO1FBQzlCLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxPQUFPLEVBQUU7UUFDUCxFQUFFLEVBQUUsU0FBUztRQUNiLElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLHdCQUF3QjtRQUM5QixZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBb0JqQjtLQUNFO0NBQ0YsQ0FBQztBQUVGLCtFQUErRTtBQUMvRSxPQUFPO0FBQ1AsK0VBQStFO0FBRS9FOztHQUVHO0FBQ0gsU0FBUyxrQkFBa0IsQ0FBQyxVQUFrQjtJQUM1QyxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxPQUFPLElBQUksQ0FBQyxLQUFLLENBQUMsT0FBTyxDQUFDLENBQUM7QUFDN0IsQ0FBQztBQUVEOztHQUVHO0FBQ0g7O0dBRUc7QUFDSCxTQUFTLFlBQVksQ0FBQyxVQUFrQjtJQUN0QyxNQUFNLFVBQVUsR0FBRyxHQUFHLFVBQVUsV0FBVyxJQUFJLENBQUMsR0FBRyxFQUFFLEVBQUUsQ0FBQztJQUN4RCxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxFQUFFLENBQUMsYUFBYSxDQUFDLFVBQVUsRUFBRSxPQUFPLEVBQUUsT0
...[truncated 27 chars]

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · dist/index.js (reported line 800)May include surrounding context.

js
}
}
exports.default = main;
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi9zcmMvaW5kZXgudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IjtBQUFBOzs7Ozs7Ozs7OztHQVdHOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztBQWdqQkgsb0JBa1VDO0FBLzJCRCx1Q0FBeUI7QUFDekIsMkNBQTZCO0FBa0U3QiwrRUFBK0U7QUFDL0Usa0JBQWtCO0FBQ2xCLCtFQUErRTtBQUUvRSxNQUFNLGVBQWUsR0FBa0M7SUFDckQsSUFBSSxFQUFFO1FBQ0osRUFBRSxFQUFFLE1BQU07UUFDVixJQUFJLEVBQUUsS0FBSztRQUNYLElBQUksRUFBRSw4QkFBOEI7UUFDcEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBc0JqQjtLQUNFO0lBQ0QsR0FBRyxFQUFFO1FBQ0gsRUFBRSxFQUFFLEtBQUs7UUFDVCxJQUFJLEVBQUUsTUFBTTtRQUNaLElBQUksRUFBRSwwQkFBMEI7UUFDaEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQW9CakI7S0FDRTtJQUNELE9BQU8sRUFBRTtRQUNQLEVBQUUsRUFBRSxTQUFTO1FBQ2IsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsMEJBQTBCO1FBQ2hDLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxHQUFHLEVBQUU7UUFDSCxFQUFFLEVBQUUsS0FBSztRQUNULElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLDBCQUEwQjtRQUNoQyxZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQXFCakI7S0FDRTtJQUNELEdBQUcsRUFBRTtRQUNILEVBQUUsRUFBRSxLQUFLO1FBQ1QsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsd0JBQXdCO1FBQzlCLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxPQUFPLEVBQUU7UUFDUCxFQUFFLEVBQUUsU0FBUztRQUNiLElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLHdCQUF3QjtRQUM5QixZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBb0JqQjtLQUNFO0NBQ0YsQ0FBQztBQUVGLCtFQUErRTtBQUMvRSxPQUFPO0FBQ1AsK0VBQStFO0FBRS9FOztHQUVHO0FBQ0gsU0FBUyxrQkFBa0IsQ0FBQyxVQUFrQjtJQUM1QyxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxPQUFPLElBQUksQ0FBQyxLQUFLLENBQUMsT0FBTyxDQUFDLENBQUM7QUFDN0IsQ0FBQztBQUVEOztHQUVHO0FBQ0g7O0dBRUc7QUFDSCxTQUFTLFlBQVksQ0FBQyxVQUFrQjtJQUN0QyxNQUFNLFVBQVUsR0FBRyxHQUFHLFVBQVUsV0FBVyxJQUFJLENBQUMsR0FBRyxFQUFFLEVBQUUsQ0FBQztJQUN4RCxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxFQUFFLENBQUMsYUFBYSxDQUFDLFVBQVUsRUFBRSxPQUFPLEVBQUUsT0
...[truncated 27 chars]

Static analysis

No suspicious patterns detected.