Back to skill

Security audit

智能代码审查助手

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language code review skill with no bundled executable code or hidden persistent behavior, though its documented review script is not present in the artifact.

Before installing, be aware that the documentation is Chinese-only and the artifact references a Node review script that is not included here. If installation later downloads or exposes additional files, inspect that actual script before running it on private code.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documentation is entirely in Chinese and does not indicate that other languages are supported for the user-facing instructions. This creates a natural-language policy concern because it effectively imposes a locale/language choice without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the main markdown content are written entirely in Chinese, which creates an implicit language requirement for users. The file does not mention that the skill is China-specific, nor does it offer an alternative language or user opt-in for locale/language preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.