Back to skill

Security audit

内容归档工具-免费版

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it is a persistent full-content archiving skill with overbroad activation language and under-scoped command/API authority.

Install only if you are comfortable with the agent saving full copies of content and related history under a persistent local archive. Restrict use to material you are authorized to archive, review any shell commands before execution, and consider disabling or manually controlling proactive recall for sensitive work.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest presents the skill as a content archiving tool, but the body expands its scope to broad AI orchestration, API integration, file handling, and command execution. This capability mismatch can cause overbroad invocation and grant operators more powerful behaviors than users would reasonably expect from the advertised purpose.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill advertises generic command execution even though its stated purpose is personal content archiving. Unnecessary exec capability increases the attack surface substantially because an agent may run shell commands in contexts where users only expected document capture and search.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill claims broad external API integration unrelated to the narrow archive-tool purpose. This can enable unreviewed outbound data flows and make it easier for archived content or user inputs to be sent to third-party services without clear necessity or consent.

Vague Triggers

High
Confidence
96% confidence
Finding
The activation scope is so broad that the skill could be selected for many unrelated AI, orchestration, or automation tasks beyond archival use. Overbroad routing is dangerous because it can cause a high-privilege skill with exec/browser capabilities to activate in contexts where its data retention and command features are unnecessary.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill emphasizes capturing and permanently saving full external content but does not clearly address privacy, copyright, retention limits, or consent. In practice, this can lead to unauthorized storage of personal, proprietary, or licensed material and create downstream compliance and data exposure risks.

Ssd 3

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to persistently store full content, semantic metadata, and access/search history, then proactively resurface that data later. This creates a durable data aggregation and leakage risk, especially when archived content may include sensitive information or when proactive recall exposes prior material in unrelated contexts.

Ssd 3

Medium
Confidence
96% confidence
Finding
The examples and storage layout normalize preserving complete original content and interaction history in natural-language files. Centralizing such material in searchable Markdown increases the chance of accidental disclosure, overcollection, and later retrieval of sensitive information beyond the user's original intent.

Static analysis

No suspicious patterns detected.