Back to skill

Security audit

OpenRank

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public OpenDigger metrics for user-specified open source repositories or developers and does not request unusual local access, persistence, or credential handling.

Before installing, understand that the skill may make network requests to OpenDigger's public OSS data host for repository or developer names you provide. It does not appear to access private files or credentials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary functional description and usage context are written in Chinese, while the file also includes English examples later. This creates a language policy concern because the skill documentation appears to privilege a specific language without explicit user opt-in or a stated region-specific reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The expected output explicitly requires 'A Chinese summary report', which encodes a language requirement in the skill's natural-language behavior. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation, and no alternative or opt-in mechanism is documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The expected output mandates 'An English summary report', which imposes a specific language in the evaluation criteria. The file does not indicate that the user is offered a language choice or that the English-only requirement is justified by a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This expected output requires 'A comprehensive Chinese Markdown table', which fixes the response language. Because the file does not describe an opt-in or a justified locale restriction, this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The expected output requires 'A comprehensive English Markdown table', imposing a fixed language requirement. No language-choice mechanism or justified locale constraint is present in this file, so it may violate the language/locale policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.