Back to skill

Security audit

liebin

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent design-review workflow, with some privacy and scope considerations when using URLs, local code paths, or optional browser scripts.

Install only from the reviewed ZIP or a trusted repository state. Use this skill with user-approved URLs, screenshots, and local paths, and avoid giving it private repositories, staging sites, or sensitive customer content unless that access is intended for the design task. Treat the optional Node and Playwright scripts as local helpers for generating previews and verification reports.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (65)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes an end-user design assistance skill focused on creating three visual design options, capturing user choices, and validating implemented pages against prior design decisions. The actual code does none of that. It is an infrastructure/build script for packaging skill assets into a ZIP file for distribution. Its primary purpose, inputs, outputs, and behavior are materially different from the declared description. This is a clear mismatch, not merely a supporting implementation detail, because the code chunk itself is about packaging artifacts rather than implementing the described design workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a high-level design exploration and decision-capture workflow: render three competing design samples from real user content, compare them, and generate a DESIGN.md documenting decisions. The actual code does none of that. Instead, it defines web components and supporting UI behavior for slide decks and image placeholders. The primary behavior is rendering and managing presentation slides and persisted image slots, including editing affordances, host messaging, localStorage usage, fetch/write of a state JSON sidecar, and print/export support. These are materially different capabilities and purposes from the declared design-consultation workflow. This is not just an implementation detail mismatch; the code's core functionality is unrelated to the described skill behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a high-level design workflow skill whose core job is to create three candidate visual directions, help the user choose among them, and record decisions in DESIGN.md before any HTML is written. The supplied code instead is ordinary frontend implementation code: a custom image-slot web component for image framing/editability, a set of UI primitives (Badge, Button, SectionHead, etc.), and a fully realized homepage composed from hardcoded data arrays and React components. This is a materially different primary purpose. While it is still design/UI-related in a broad sense, the specific promised workflow capabilities—multi-option mockup generation, comparison, decision capture, design-document output, and acceptance validation—are absent. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个‘设计决策/方案确认’型 skill,核心能力应是先产出三个设计变体、引导用户取舍,并回写 DESIGN.md,甚至支持后续验收比对。而实际代码只是一个用于 liebin 落地页的浏览器端工具脚本,主要功能是页面交互、安装命令切换、本地文件收集,以及把用户输入整理成 BRIEF.md 并打包成 zip。虽然 buildBrief() 中的文案提到了“定轴→三个变体×三屏→回写 DESIGN.md”,但代码本身并没有实现这些设计产出或验收逻辑,只是在为后续流程准备输入材料。因此主用途与声明不一致,且代码表现出若干未在声明中体现的前端站点/打包能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a high-level UX/design workflow for generating and comparing three visual design proposals and writing DESIGN.md documentation. The supplied code does none of that. Instead, it implements a generic browser runtime for rendering custom design-component documents with React, including template parsing, expression resolution, dynamic component loading, streaming updates, external module execution, and head/helmet management. This is not a supporting implementation of the declared workflow; it is a fundamentally different capability set and primary purpose. The description also omits sensitive behaviors such as network fetching, execution of embedded/external code, DOM/head mutation, and cross-window messaging.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
node scripts/proof.mjs --in proof/ --out proof.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
node scripts/proof.mjs --in proof/ --out proof.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
node scripts/verify-page.mjs --url http://localhost:8000 --proof 样张截图.png --out verify/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
node scripts/verify-page.mjs --url http://localhost:8000 --proof 样张截图.png --out verify/

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/preview-template.html (reported line 2)May include surrounding context.

html
<!DOCTYPE html>
<!--
  列宾 · 三变体确认样张模板
  用法:复制此文件,替换所有 {{...}} 占位,并在 .stage 内写入每个变体每一屏的真实渲染。
  约束:单文件、内联一切、除 Google Fonts 外无外部依赖、不要用 localStorage。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/preview-template.html (reported line 2)May include surrounding context.

html
<!DOCTYPE html>
<!--
  列宾 · 三变体确认样张模板
  用法:复制此文件,替换所有 {{...}} 占位,并在 .stage 内写入每个变体每一屏的真实渲染。
  约束:单文件、内联一切、除 Google Fonts 外无外部依赖、不要用 localStorage。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · site/downloads/liebin-skill.zip!/liebin/assets/preview-template.html (reported line 2)May include surrounding context.

html
<!DOCTYPE html>
<!--
  列宾 · 三变体确认样张模板
  用法:复制此文件,替换所有 {{...}} 占位,并在 .stage 内写入每个变体每一屏的真实渲染。
  约束:单文件、内联一切、除 Google Fonts 外无外部依赖、不要用 localStorage。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · site/downloads/liebin-skill.zip!/liebin/assets/preview-template.html (reported line 2)May include surrounding context.

html
<!DOCTYPE html>
<!--
  列宾 · 三变体确认样张模板
  用法:复制此文件,替换所有 {{...}} 占位,并在 .stage 内写入每个变体每一屏的真实渲染。
  约束:单文件、内联一切、除 Google Fonts 外无外部依赖、不要用 localStorage。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The runtime evaluates JavaScript taken directly from component document content via Function/new Function, allowing embedded component logic to execute with full page privileges. That capability is far broader than the skill’s stated design-comparison purpose, so any untrusted design artifact can become arbitrary script execution in the browser.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section implements a generic external code loader with transpilation and execution of fetched JS/JSX, effectively acting as a mini plugin system. That is dangerous because an attacker can supply or influence imported module URLs and gain arbitrary script execution in the page context, which is unrelated to the skill’s narrow design-confirmation workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Helmet processing copies SCRIPT elements from component markup into the document head, causing arbitrary script execution from template content. Because the skill processes user-supplied or model-generated design artifacts, this turns markup rendering into an execution sink and makes XSS/trusted-template abuse highly likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation is entirely Chinese and appears to prescribe fixed Chinese-language interaction without stating whether other languages are supported. In an agent setting, this can cause language-locking behavior where the skill responds in Chinese despite the user's preferred language, leading to misunderstanding, incorrect requirements capture, and reduced user control.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match common design- or webpage-related requests, which can cause the skill to activate in situations the user did not explicitly intend. That creates prompt-routing risk: the agent may be steered into this skill's workflow instead of following the user's direct request, potentially causing unnecessary data collection, confusion, or unintended behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill explicitly instructs the agent to read local paths, fetch live URLs, and run local/node scripts, but it declares no tool scope or permission boundary. Without an explicit allowlist, an agent may overreach into file, network, or environment access beyond what the user expected, increasing the chance of unintended data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance uses broad phrases like '帮我设计一下' and '做个落地页/UI/PPT 的视觉', which can trigger on ordinary user requests and cause the agent to pivot into this workflow unexpectedly. Over-broad triggering is risky because this skill asks for URLs, local paths, and real content, so accidental invocation can expand data collection and actions beyond user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to request live site URLs and local code paths to gather real copy and page context, but it provides no warning about privacy, secrets, or proprietary code exposure. In practice this can lead users to disclose internal staging URLs, repository locations, or sensitive content to tools that may read more than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file references a “中文排版扩展,” and elsewhere the instructions and fixed labels are all prescribed in Chinese, but there is no indication that the user can opt into another language or that the skill is intentionally limited to Chinese-language use. This can violate language/locale policy when the skill is applied to users who have not requested Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document declares lang="zh-CN" and all visible instructions, labels, and prompts are written in Chinese, which forces a specific language/locale for end users. The file does not offer localization, opt-in language selection, or any explanation that this template is intentionally limited to a China-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The expected output explicitly requires Chinese deliverables, and multiple assertions reinforce Chinese-only content requirements. Because this is a natural-language policy constraint in a JSON eval file and there is no user opt-in or documented regional justification, it fits the locale-policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This assertion mandates exact Chinese labels for the three variants, which constrains the skill's language behavior regardless of user preference. No alternative language path or justification is provided in the file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/proof.mjs:174

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/proof.test.mjs:28

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
site/support.js:844