Back to skill

Security audit

SSL证书查询

Security checks for vulnerabilities and agentic risk

Overview

This skill is a purpose-aligned SSL certificate checker with some disclosed batch-monitoring behavior and minor implementation cautions.

Install only if you are comfortable with a Chinese-language SSL checker that may use a local domains list for batch checks. Review or control the domains file before running the script, and avoid trusting its JSON output in automation unless the JSON escaping issue is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
check-ssl.sh:58
Finding

Unescaped Domain Data Enables JSON Output Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个按自然语言触发、查询某个指定域名证书过期时间的技能。实际代码并不解析用户给出的单个域名,而是依赖本地 ssl-domains.txt 文件进行批量检查,这使其主要用途更接近“SSL 证书监控器”而非“单次查询工具”。此外,代码会访问并在缺失时创建本地文件,进行阈值告警分级、汇总统计、JSON 输出以及通过退出码表示失败状态,这些都是未在描述中体现的能力。虽然核心主题仍与 SSL 证书到期检查相关,但其实际行为和资源访问方式与声明存在实质差异,因此应判定为描述与行为不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description and usage instructions require Chinese phrasing such as 「查 xxx.cn 证书」 and present the skill entirely in Chinese, which indicates a language-specific constraint. The file does not provide user opt-in, alternative language support, or a documented justification that this is a region-specific skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata says it checks a user-specified domain's SSL certificate, but the implementation ignores that model and instead reads a local batch file, with behavior centered on monitoring a persistent domain list. This mismatch is dangerous because users or calling agents may provide a single domain expecting a read-only query, while the script performs broader, stateful operations that can inspect unintended hosts and behaves differently than advertised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When the expected domains file is missing, the script creates directories and writes a template file under the user's home directory, even though the stated purpose is just querying certificate expiry. Unnecessary filesystem writes expand the skill's side effects and can violate user expectations or agent sandbox assumptions, especially in automation contexts that expect read-only inspection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill title and all example invocations are presented only in Chinese, including the user trigger phrases in the usage section. This can constitute a language/locale policy issue because the documentation implicitly requires Chinese-language use without giving users an explicit language option or stating that the skill is intentionally China/Chinese-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.