Back to skill

Security audit

Nas system monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a simple local NAS monitor, but it materially overstates remote alerting and monitoring features that the shipped code does not implement.

Review this carefully before installing if you need real unattended NAS alerting: the current artifact does not send Feishu, Discord, or Telegram notifications and does not implement several advertised monitoring checks. It is suitable only as a local, foreground prototype unless those gaps are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
monitor.py:78
Finding

Remote security notifications are silently discarded

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
monitor.py:52
Finding

CPU temperature monitoring failures are silently suppressed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
monitor.py:43
Finding

Memory monitoring fails when the monitor is imported as a module

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The documented behavior does not match the apparent implementation: key claims such as Feishu/Discord alerting and network monitoring are described as supported while analysis indicates they are incomplete or placeholder-only. This is dangerous because operators may rely on the skill for security-relevant monitoring and alert delivery that does not actually occur, leading to missed incidents or delayed response.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises or implies shell-based operational capability but does not declare any explicit tool scope such as permissions or allowed-tools. This creates a least-privilege and transparency problem: an agent or user may invoke shell-capable behavior without a clearly bounded execution policy, increasing the risk of unintended command execution against the NAS host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file header and later user-facing strings indicate the skill presents operational output in Chinese, but there is no opt-in, language selection, or justification that the skill is region-specific. This can violate a language/locale policy when users are not given a choice.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · monitor.py (reported line 26)May include surrounding context.

python
def check_disk_usage(self):
        """检查磁盘使用率"""
        result = subprocess.run(['df', '-h'], capture_output=True, text=True)
        lines = result.stdout.strip().split('\n')[1:]
        
        for line in lines:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says it monitors NAS health and auto-alerts via Feishu/Discord. However, the notification function is a stub with a TODO and no outbound messaging logic, so the code does not actually perform the described alert delivery behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The main descriptive content begins in Chinese and the feature list continues in that language, with no indication that other languages are supported or that the user can choose a preferred locale. This can violate language/locale policy expectations when a skill forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.