Back to skill

Security audit

Tool Permission Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a permission-management guide, but it allows broad natural-language permission changes without enough safeguards.

Review this skill carefully before installing. It should define a narrow command format, explicit confirmation, allowed tool lists, role checks, logging, and rollback behavior before being trusted to manage permissions for command execution, file writes, messaging, cron jobs, or session controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill enables dynamic permission changes for sensitive tools but does not clearly warn users about the risks or describe safeguards such as authentication, confirmation, or scope restrictions. Because the document governs tool authorization, omission of strong warnings and controls makes privilege escalation or accidental enabling of dangerous tools like exec, write, message, or cron more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase allowing users to dynamically adjust permissions via natural language such as "授权XXX工具" is overly broad and can easily collide with ordinary conversation or be triggered indirectly. In a permission-management skill, ambiguous activation/configuration language is risky because it could cause unintended privilege changes without an explicit, well-scoped authorization flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file presents the skill description and operating instructions in Chinese, with no indication that another language can be chosen or that Chinese is a required locale. This can violate language/locale policy when users are not given an explicit opt-in or alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.