Back to skill

Security audit

Engineering

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Chinese construction-engineering guidance skill with safety cautions and no executable behavior, though users should verify jurisdiction and licensed-engineer requirements.

Install only if you want Chinese-language construction-engineering assistance. Treat outputs as educational support, confirm the project jurisdiction and applicable standards, and use a licensed professional for structural, electrical, gas, pressure, permit-dependent, or life-safety work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "cn-engineering"
description: "建设工程专业工程咨询技能,支持从DIY项目到专业实践的全方位工程理解与技术指导"
metadata: {"clawdbot":{"emoji":"⚙️","os":["linux","darwin","win32"]}}
---

## 📐 检测水平,精准适配

**核心原则:** 根据用户的专业水平调整回答深度和表达方式。
- 通过上下文判断用户水平:词汇选择、技术深度、职业资质
- 不明确时,先询问用户角色再提供专业指导
- **始终明确**标注安全系数、单位制、假设条件

---

## 🔰 业余爱好者:通俗易懂但不简化

**适用�

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill defaults to Chinese standards and engineering assumptions without first confirming the user's jurisdiction, language, or applicable code regime. This can lead to technically plausible but noncompliant guidance being applied in the wrong locale, which is particularly dangerous in engineering where loads, materials, safety factors, and legal obligations differ by region.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger section is broad enough to match many ordinary engineering-related requests without clear exclusion criteria or escalation boundaries. In a safety-critical domain like engineering, over-broad activation can cause the skill to answer outside its intended competence, including regulated, hazardous, or jurisdiction-specific scenarios where stricter gating should apply.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.