Back to skill

Security audit

ManualGen

Security checks for vulnerabilities and agentic risk

Overview

This documentation skill has a coherent goal, but it asks the agent to automatically scan and modify projects while asserting control over the session without clear user approval.

Install only if you explicitly want a fully managed, Chinese-language manual-generation workflow that can read a whole project, create persistent .agent/harness artifacts, run its bundled Python validator, and write documentation files. Confirm the target project path first, keep generated harness data out of commits, run an independent secret scan on all generated artifacts, and avoid using purge/reset on paths you have not verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:31
Finding

Skill Instructions Attempt to Override the Host Agent and Obstruct Independent Auditing

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:100
Finding

Broad Semantic Activation Causes Unconfirmed Persistent Project Modification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
manualgen_tools/run.py:99
Finding

Mandatory Privacy Policy Is Not Enforced by the Machine Validation Gate

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
manualgen_tools/run.py:774
Finding

Destructive Reset Recursively Deletes a Directory Derived from an Unrestricted Input Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (104)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The overview explicitly states that once activated, the skill proceeds through an 18-stage autonomous state machine, '无需用户下命令、不询问用户决策', and later writes JSON artifacts and updates baton state. This creates a high-risk autonomous file-modification workflow without an explicit warning, approval gate, or per-write consent, increasing the chance of silent workspace changes and cascading unintended operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entity alignment step permits automatic merges even when uncertainty remains, and then rewrites node identities and redirects all related triples downstream. In this skill’s context, that can silently corrupt the knowledge graph, conflate distinct business entities, and propagate incorrect relationships through later confidence, snake, and manual-generation stages, making recovery difficult.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest presents the skill as a manual-generation expert, but the body adds substantial operational behavior: verification, leakage scanning, coverage enforcement, baton repair/reset, and broad filesystem orchestration. This is risky because users may invoke it for documentation help without realizing it performs auditing, repair, and state-management actions inside the target project.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
| **工程骨架层(强约束)** | 机器 | `run.py` | 文件存在性、批次计数、产物清单、覆盖完整性、技术泄漏、接力棒计数反推 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 591)May include surrounding context.

md
| **工程骨架层(强约束)** | 机器 | `run.py` | 文件存在性、批次计数、产物清单、覆盖完整性、技术泄漏、接力棒计数反推 |

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly states it activates whenever the user expresses manual-writing or project-analysis intent, which creates ambiguous invocation boundaries. Because activation immediately transitions into multi-step autonomous processing, this ambiguity can cause unintended execution on real project paths and sensitive codebases.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to create directories, initialize baton state, and run CLI verification immediately upon activation, without a clear consent checkpoint. This is dangerous because it performs write operations and command execution before the user has explicitly acknowledged filesystem impact.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a documentation-generation skill that progressively analyzes UI/modules/functions to produce a user manual. This file instead defines a separate autonomous conflict-resolution agent that adjudicates graph inconsistencies, mutates knowledge-graph nodes/triples, and updates confidence metrics, which is a materially different operational role than manual generation itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly removes interactive confirmation and instructs the AI to resolve conflicts 100% autonomously, which materially increases the risk of unsafe or incorrect persistent changes. In this context, the danger is not just bad documentation output: the resolver also records decisions and modifies graph artifacts, so non-interactive operation can institutionalize errors at scale without human review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill is written to operate in Chinese and provides no indication that the user can choose another language or locale. Under the policy, forcing a specific language without explicit opt-in is a natural-language policy violation unless the locale restriction is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · knowledge-base/00-schema.md (reported line 313)May include surrounding context.

md
"type": "delete",
 "entry": {
 "page": "/customer/list",
 "api": "DELETE /api/v1/customers/:id"
 }
 }
 ],

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keywords are generic phrases such as '生成文档', '用户手册', and '更新文档' that are common in ordinary user requests, so this skill may trigger outside its intended niche. Because the skill requests broad read/write capabilities and can write output into the project root, accidental activation increases the chance of unintended file access, workspace modification, or workflow hijacking.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The intent regexes are broad patterns like '帮我.*手册' and '需要.*操作手册', which can match many benign requests that do not require this powerful documentation agent. In this skill's context, ambiguous auto-selection is more dangerous because the skill is designed for deep project analysis, persistent runtime state, and document generation, so an overmatch can cause unnecessary data processing and writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill title and all user-facing invocation/documentation content in this README are written exclusively in Chinese, and the examples assume Chinese-language commands. Under the policy, a skill should not force a specific language or locale unless it offers user choice or clearly documents a justified regional constraint, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The entire skill overview, triggers, status text, and user-interaction phrases are specified only in Chinese, with no indication that users may choose another language. This can violate language/locale policy when a skill implicitly forces one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill auto-activates on very broad phrases like '写手册/分析项目', which can cause unintended invocation during normal conversation. Because the workflow then immediately reads state and performs autonomous file-writing steps, accidental triggering can lead to unexpected actions without clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The pause/continue behavior says execution resumes automatically if the user says '继续' or even if the next message '不说别的', while the workflow is designed to keep writing progress artifacts. This weakens user control and can cause autonomous writes to restart without a fresh warning or confirmation that persistent changes will continue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all operational guidance exclusively in Chinese, which can impose a fixed language/locale on users or agents without any documented opt-in. The policy explicitly calls for flagging language or locale constraints when the skill does not offer a choice or justified limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document title and the entire operational specification are written as Chinese-only instructions, with no indication that the user may choose another language or locale. Under the policy, a skill that effectively requires a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill requires automatic write-back of merged results into graph files as a mandatory step, while the broader skill repeatedly emphasizes autonomous operation without asking the user. Unprompted file modification is dangerous because it can overwrite prior state, propagate incorrect inferences, and make forensic review harder if changes are applied automatically to project artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction requires Mermaid node text to use '用户语言', while the surrounding skill content is explicitly written in Chinese and does not offer a language choice or opt-in mechanism. This creates a locale policy concern because the skill appears to assume a fixed language context rather than allowing the user to select their preferred language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to invoke external Python tooling (python run.py scan_tech) over project and manual paths, expanding behavior from document generation into local command execution. Even if framed as quality control, this increases attack surface because the tool behavior, working directory, and target paths may be influenced by repository content or environment state, and the user is not clearly asked to approve command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to run automatic quality-gate commands after sub-agent review, but does not provide user-facing disclosure or consent for command execution. Hidden subprocess behavior is risky because users may believe the skill only writes documentation while it actually executes local programs against repository paths and generated content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The integration phase mandates multiple external commands (scan_tech, coverage, verify) as hard quality gates, which gives the skill generalized command-execution capability beyond its stated purpose of producing a user manual. This is risky because a skill for authoring documentation should not silently gain authority to execute local tooling across the project, especially as part of a required delivery path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill content mandates Chinese-language instructions and output phrasing, including fixed Chinese labels and report text, but does not state that language selection is optional or user-chosen. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.