Back to skill

Security audit

cp2k-input-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill locally helps generate CP2K input files and shows no evidence of hidden network access, credential use, persistence, or destructive behavior.

Before installing, treat this as a Chinese-language CP2K input helper. Confirm the output path before writing so an existing .inp file is not overwritten, and manually review generated inputs for advanced workflows like NEB, frequency, QMMM, MM, or CP2K-output reuse because those are not fully implemented by the bundled script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The core declared purpose and actual primary behavior are aligned at a high level: this code does generate CP2K input files from structural files. However, the description materially overstates supported scope. The implementation only handles structure-file inputs (xyz/cif/pdb/Gaussian), not CP2K output files. It supports energy, geometry optimization, and MD generation, but not frequency analysis or NEB. It also does not provide distinct QMMM or MM generation logic; the produced template is centered on CP2K DFT/Quickstep sections. These are substantive capability mismatches rather than minor implementation details, so the description does not accurately represent the supplied code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

该技能文档从标题到全部使用说明均以中文呈现,并在示例中默认用户以中文提出请求,没有提供可选语言、双语支持或明确的地区限定说明。根据规则,若技能在自然语言层面强制特定语言而没有用户选择或合理限定,属于语言/locale 策略违例。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs use of file-reading and file-writing capabilities (read_file, write_to_file) but does not declare any tool scope or allowed-tools restrictions. In an agent environment, missing scope declarations can let the skill access or modify files more broadly than intended, increasing the chance of unauthorized workspace data exposure or overwriting user files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation tells the agent to invoke an auxiliary Python script to generate inputs, which introduces code-execution/subprocess behavior beyond simple text/file transformation. If the script path, arguments, or surrounding environment are attacker-controlled, this can lead to execution of unintended code or unsafe processing of untrusted files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The trigger list includes the English phrase "CP2K calculation input" while the rest of the skill is written primarily in Chinese, and the document does not state whether outputs should follow the user's preferred language. This can create a language-policy issue because the skill implicitly supports or steers a specific language without explicit user opt-in or a documented language-selection rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

该 markdown 文件标题和全文均以中文编写,但未说明这是面向特定中文用户群体的区域性文档,也未提供语言选择或用户选择机制。根据语言/区域策略,强制单一语言而无用户选择可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.