Back to skill

Security audit

test转储

Security checks for vulnerabilities and agentic risk

Overview

The skill is not overtly malicious, but it describes unattended automation that imports data into another system over plaintext HTTP with limited safeguards.

Review before installing. Use only in a controlled test or low-risk environment unless you add HTTPS endpoints, pinned dependencies, explicit approval before import, validation of exported row counts/content, logging, and a rollback plan. Avoid enabling the cron job until the import is proven idempotent and monitored.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Third-Party Dependencies and Browser Artifacts

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

Plaintext HTTP Transport for Data Collection and Upload

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly describes exporting data from one system and importing it into another, but it does not warn users that it will perform state-changing actions in the target system. This creates risk of unintended data modification, propagation of incorrect data, and misuse in unattended or poorly reviewed runs, especially because the target operation is an automated import rather than a read-only action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The cron example encourages unattended recurring execution of an automated export/import workflow without warning that it will continuously move data and trigger write operations in another system. This increases the chance of repeated bad imports, duplication, stale-data propagation, or large-scale operational impact if selectors break or source data changes unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.