Back to skill

Security audit

skill-medic

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local Skill health checker, but it needs Review because it broadly reads other installed skill instructions and can persist/update audit state without a strong untrusted-content or approval boundary.

Install only if you are comfortable letting it inspect your installed Skill directories and write audit state under .medic. Prefer running it on a limited workspace scope first, review generated reports before acting on deletion/merge advice, and avoid rubric web updates unless you explicitly want the skill to use online standards and change its stored rubric metadata/files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
medic_tools/run.py:1210
Finding

Indirect Prompt Injection Through Untrusted Skill and Web Content

Content
View full analysis
str: """ Collect Skill "implementation declaration" text (tool-layer py + SKILL.md + agents/protocols + references/mcp-reference.md) for static resource-reference comparison. """ tool_texts: list[str] = [] body_texts: list[str] = [] if os.path.isdir(skill_dir): for entry in sorted(_safe_listdir(skill_dir)): if not is_tools_dir(entry) or entry == "medic_tools": continue tp = os.path.join(skill_dir, entry) if not os.path.isdir(tp): continue try: tool_files = os.listdir(tp) except OSError as e: print(f"Warning: unable to read tool directory {tp}: {e}") continue for f in tool_files: if f.endswith(".py") and f != "__init__.py": fp = os.path.join(tp, f) try: with open(fp, "r", encoding="utf-8", errors="ignore") as fh: tool_texts.append("\n".join(fh.readlines()[:300])) except Exception as e: print(f"Warning: failed to read {fp}: {e}") skill_md = os.path.join(skill_dir, "SKILL.md") if os.path.isfile(skill_md): content, _ = read_file_safe(s ...[truncated 5842 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个完整的 Skill 审计与治理工具,但实际代码片段只有一个空的包初始化文件注释,没有任何执行逻辑。从当前提供的代码来看,既没有访问已安装 Skill 的机制,也没有分析、比较、评分或输出建议的实现。因此代码行为与声明用途存在明显不一致,属于声明了重要能力但代码未体现。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
- 所有静态分析统一通过 `medic_tools/run.py` 执行(定位/调用/失败处理详见 `references/cli-guide.md`)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow mandates a final run.py cleanup <root> step yet does not require explicit consent or describe exactly what will be removed. Cleanup operations are inherently destructive; if path handling is flawed or the root is broader than intended, important artifacts or unrelated files could be deleted, making this more dangerous than routine baton-file writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest sets language: zh-CN, and the skill name/description are also written in Chinese, which indicates a fixed language/locale for the skill. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese and does not indicate that the skill is region-specific or that users may choose another language. Per the policy scope, forcing a specific language without opt-in is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · CHANGELOG.md (reported line 376)May include surrounding context.

md
- **成熟度标签通俗化**:L3~L0 从"成熟/可用/玩具 Demo/残缺僵尸"改为"放心用 / 基本能用 / 不太成熟 / 不建议用"(chunk-05 对照表 + 报告统一用通俗标签,L 级仅括号备注)
- **报告 9 部分结构**(chunk-07 + run.py build_report):新增"一句话总结"、"冲突影响你什么(含自然语言唤醒举例)"、"给普通用户的行动建议"、"通俗评估列",历史对比改为"上次的问题解决了吗"
- **统一清理**:chunk-02/06/08/09、agents、faq-deep、CHANGELOG、run.py 注释中的"军团/体检/玩具/僵尸/验尸官"等表述全部改为日常语言
- **重复安装识别落地**:scan_skills 不再静默丢弃同名 Skill,重复安装位置记入 `dup_sources`,报告"冲突与问题"区新增"重复安装"展示(例:同一 Skill 在 `.trae/skills` 与 `.claude/skills` 各装一份 → 建议只保留一份)
- 验证:py_compile 通过

## v0.3.4 (2026-08-05)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · CHANGELOG.md (reported line 376)May include surrounding context.

md
- **成熟度标签通俗化**:L3~L0 从"成熟/可用/玩具 Demo/残缺僵尸"改为"放心用 / 基本能用 / 不太成熟 / 不建议用"(chunk-05 对照表 + 报告统一用通俗标签,L 级仅括号备注)
- **报告 9 部分结构**(chunk-07 + run.py build_report):新增"一句话总结"、"冲突影响你什么(含自然语言唤醒举例)"、"给普通用户的行动建议"、"通俗评估列",历史对比改为"上次的问题解决了吗"
- **统一清理**:chunk-02/06/08/09、agents、faq-deep、CHANGELOG、run.py 注释中的"军团/体检/玩具/僵尸/验尸官"等表述全部改为日常语言
- **重复安装识别落地**:scan_skills 不再静默丢弃同名 Skill,重复安装位置记入 `dup_sources`,报告"冲突与问题"区新增"重复安装"展示(例:同一 Skill 在 `.trae/skills` 与 `.claude/skills` 各装一份 → 建议只保留一份)
- 验证:py_compile 通过

## v0.3.4 (2026-08-05)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill description and usage guidance are written in Chinese, and the file does not indicate that the skill is intended only for Chinese-speaking users or provide any opt-in language choice. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents the skill overview and operational instructions entirely in Chinese, including the core one-line description of what the skill does, with no indication that language is selectable or that Chinese is required for a documented regional purpose. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs saving scan results to .medic/_medic_inventory.json without any user-facing warning that it will create or modify files in the workspace. Silent workspace writes are risky because they can alter repository state, interfere with user workflows, and create persistence artifacts users did not request or notice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

L07-L17 明确把本 Skill 定位为只看 Skill 是什么、和谁重复、体积多大,不深挖内部运作,并在 L13 进一步写明“不逐行审代码、不读 config 值”。但 L50 要求从“实现声明文件”通用提取多类内部资源依赖,这已经超出纯外部清单盘点,转向对技能内部实现与依赖面的分析。该能力与 manifest 中“列出清单、找重复冲突、评估成熟度并给出处置建议”的对外定位不完全一致。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Mandating use of the IDE Write tool to overwrite .medic/_medic_inventory.json gives the skill an unnecessary workspace-modification capability relative to its stated purpose of inspection and recommendation. Even if the target file is constrained, forced writes can surprise users, overwrite prior state, or be abused as a stepping stone for unintended persistence in the project workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Requiring the IDE Write tool to overwrite .medic/_medic_inventory.json without warning about overwrite behavior creates an avoidable integrity risk. In the context of a diagnostic skill, automatic overwrites are more dangerous because users reasonably expect observation and advice, not silent mutation of workspace files and possible loss of prior inventory data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly states that the report is for ordinary users and that the main expression should use everyday language, while the entire required title and template are fixed in Chinese. This imposes a specific language/locale on end users without any indication that they can choose another language, which matches the language-policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill permits automatic web access to fetch and incorporate external evaluation standards based on non-user-driven conditions such as 'first run' or rubric age exceeding 30 days. Even if the fetched content does not immediately alter the current scoring pass, it influences future rubric updates and stored metadata, creating a supply-chain and integrity risk without explicit user awareness or consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation condition agent == * causes this chunk to load for every sub-agent, expanding the instruction scope far beyond least-privilege. In a multi-agent skill, broadly injected routing and control rules can unintentionally override narrower agent-specific behavior, increase prompt-surface exposure, and make it easier for one compromised or malformed workflow path to influence all sub-agents.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes capabilities that involve reading and writing local files and using environment-derived context, but it does not declare any explicit tool scope or permission boundary. In a skill that inventories other installed skills and writes artifacts under .medic/, this increases the risk of over-broad file access, accidental collection of unrelated data, and unclear enforcement of least privilege.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest declares language: zh-CN, which sets a specific language/locale for the skill. Elsewhere in the file there is no indication that users may choose another language or opt in to Chinese output, so this is a natural-language locale policy issue under the stated rules.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill claims it is not a code-review or security-scanning tool and says it only performs abstract auditing, yet it also instructs use of a CLI for static analysis and LLM-backed evidence confirmation. That mismatch can cause operators to underestimate the depth of inspection being performed, leading to broader-than-expected file analysis and trust decisions without proper consent or safeguards.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document says the skill must not read full body content, but later promises full static comparison and multidimensional scoring that would normally require deeper content access. Contradictory rules around data access are dangerous because they create room for inconsistent implementations, accidental over-collection, and bypass of user expectations about what files or content will be inspected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The controller instructions explicitly authorize filesystem writes such as creating, resetting, backing up, and later cleaning up internal skill artifacts. Even if limited to the skill’s own working files, this is still state-changing behavior that can surprise users and can destroy audit continuity or overwrite prior session data if triggered automatically without explicit confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions describe automatic creation, reset, and backup of files but do not pair them with a clear user-facing warning that the skill will modify the filesystem. In an agent setting, silent writes are risky because users may expect analysis-only behavior, while the skill can persist state, overwrite existing baton files, or alter recovery evidence during failure handling.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · agents/01-inventory-agent.md (reported line 13)May include surrounding context.

md
0. **环境自检**:先执行 `run.py ping <root>` 确认项目根可读、Skill 目录可探测(不可用时记录告警但不阻断)
1. **第一数据源 = IDE 注入的 available_skills 清单**(AI 上下文中的 name + description),
   顺着 IDE 引导走,不自己猜路径
2. 文件系统扫描(`run.py scan [--scope workspace|global] [--extra-dir <path>...]`)多编辑器兼容:workspace 候选目录(.trae/.claude/.cursor/.codex/skills 等)
   + 全局候选目录(~/.trae-cn/skills 等);用户限定范围(如"只看 workspace")时用 `--scope` 过滤;
   用户显式指定自定义 Skill 目录(如"再扫一下 D:/my-skills")时用 `--extra-dir` 追加(scope 标记为 custom,
   与 workspace/global 同流程进入清单)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · agents/01-inventory-agent.md (reported line 13)May include surrounding context.

md
0. **环境自检**:先执行 `run.py ping <root>` 确认项目根可读、Skill 目录可探测(不可用时记录告警但不阻断)
1. **第一数据源 = IDE 注入的 available_skills 清单**(AI 上下文中的 name + description),
   顺着 IDE 引导走,不自己猜路径
2. 文件系统扫描(`run.py scan [--scope workspace|global] [--extra-dir <path>...]`)多编辑器兼容:workspace 候选目录(.trae/.claude/.cursor/.codex/skills 等)
   + 全局候选目录(~/.trae-cn/skills 等);用户限定范围(如"只看 workspace")时用 `--scope` 过滤;
   用户显式指定自定义 Skill 目录(如"再扫一下 D:/my-skills")时用 `--extra-dir` 追加(scope 标记为 custom,
   与 workspace/global 同流程进入清单)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructions and output requirements are presented entirely in Chinese, which effectively imposes a language choice on users and downstream agents. The file does not indicate that Chinese is optional, user-selected, or justified as a region-specific constraint, so it conflicts with the language/locale policy described in SQP-3.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.