Back to skill

Security audit

Lifecycle Hooks

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly transparent about lifecycle automation, but it asks the agent to run background/session-end automation and write memory without enough scoping or user control.

Review this before installing if you do not want an agent to create session-end cron tasks, run heartbeat-driven checks, spawn subagents, or write daily memory logs automatically. Installation should be acceptable only if you are comfortable with lifecycle automation and can clearly control when hooks are enabled or disabled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are very broad and include natural-language requests such as “检查生命周期钩子” and “记忆自动捕获怎么配置”, which can plausibly occur in ordinary conversation. This creates a prompt/skill invocation ambiguity where the skill may activate unintentionally and perform automation behavior such as cron scheduling, memory writes, or subagent orchestration without a clearly scoped user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says the skill triggers custom actions on 'critical events' but does not define what events are in scope, who can trigger them, or what constraints apply. For a lifecycle-hook skill, ambiguous activation language increases the chance the agent will invoke automation too broadly, including on sensitive phases such as startup, message handling, or subagent execution, which can lead to unintended actions or privilege misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description contains Chinese-language text in the skill metadata, but there is no indication that the skill is intended only for Chinese-speaking users or that language choice is configurable. This may create a language/locale policy issue because the skill appears to impose a specific language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.