Back to skill

Security audit

Sub-agent Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent sub-agent orchestration protocol, but it gives delegated agents under-scoped authority to send task results to WeChat or Telegram without final user review.

Review this skill before installing if your delegated tasks may include private messages, source code, credentials, business data, or personal information. It should only be used where external notification destinations are explicitly approved and where sub-agents are not allowed to send sensitive content without main-session review.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:123
Finding

Delegated Sub-Agent Can Send Unreviewed Task Results to External Messaging Channels

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructions are written entirely in Chinese and implicitly require operation in that language, but there is no opt-in, language selection, or justification that this is a region-specific skill. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
82% confidence
Finding

This section instructs a spawned sub-session to dynamically read skills/<skill-name>/SKILL.md, where skill-name is supplied through the routine payload. Without an allowlist, path validation, or capability boundary checks, this creates a genuine skill-enumeration and potentially unauthorized skill-loading risk, allowing a caller to probe available skills or induce loading of unintended internal skill definitions.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

text
收到 [ROUTINE]
  → 读 skills/subagent-orchestrator/SKILL.md(本文件)
  → 读 skills/<skill-name>/SKILL.md(任务技能)
  → 分析任务 → 拆解 checklist
  → 在工作区创建 task.md

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This protocol explicitly instructs sub-sessions to create and update workspace files and, in some cases, directly send results to external channels like WeChat or Telegram. Because it does not require explicit user confirmation, data classification, destination validation, or safety warnings before writing or transmitting content, it creates a real risk of unintended data modification or exfiltration, especially when the sub-agent handles sensitive task material.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The protocol is written entirely in Chinese and includes Chinese-only field names and examples, which can amount to a forced language/locale constraint if this is the operative skill instruction set. The file does not indicate that users may choose another language or that the Chinese-only requirement is a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

text
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

text
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/protocol.md (reported line 21)May include surrounding context.

text
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/protocol.md (reported line 36)May include surrounding context.

text
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/protocol.md (reported line 111)May include surrounding context.

text
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The protocol explicitly allows a sub-session to send results directly to external channels such as WeChat or Telegram, even though the skill’s stated purpose is orchestration and collaboration. This expands the trust boundary and creates a data exfiltration/privacy risk, especially because delegated tasks may contain sensitive user content and the document does not define strict consent, scoping, or approval controls for external transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document describes sending task results to external messaging platforms but does not require any user-visible warning about data leaving the local/session environment. Users may reasonably assume outputs stay within the agent system, so silent transmission to third-party channels can violate privacy expectations and potentially disclose confidential information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template is entirely written in Chinese and implicitly steers generated retrospective content into Chinese without any user choice or opt-in. In a subagent orchestration skill, this can cause instruction-language mismatch, reduce transparency for users expecting another language, and lead delegated agents to produce inaccessible or policy-misaligned outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.