Back to skill

Security audit

Automation Workflows 0 1 0

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a no-code automation guide, but it asks for command-execution capability it does not need or clearly explain.

Review this before installing because it grants command execution even though the skill reads like a Markdown-only automation playbook. Prefer a version with exec removed, or only use it in an environment with command approval and sandboxing. Be careful when applying its workflow examples to CRM, email, accounting, social posting, and customer-data systems because those automations can change business records or contact customers.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:38
Finding

Unnecessary Shell Execution Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38–40 and 339–341
Vulnerability Type: Excessive tool permissions
Risk Level: Low

Evidence

yaml
tools:
- read
- exec

The capability is reiterated in the dependency notes:

text
### 可用性分类
- **分类**: MD+EXEC(纯Markdown指令,部分功能需要exec命令行执行能力)
- **说明**: 基于Markdown的AI Skill,通过自然语言指令驱动Agent执行任务

Technical Analysis

The skill declares access to the exec tool, which provides a command-execution channel. However, the audited skill body is an informational guide for designing no-code automation workflows. It contains no shell commands, local scripts, or documented operation that requires command execution.

Granting exec therefore exceeds the permissions necessary for the skill's stated purpose and violates the principle of least privilege. Although the current instructions do not directly invoke or abuse the capability, making it available increases the consequences of later prompt injection, untrusted workflow content, or unintended agent behavior.

No active command execution, embedded malicious payload, remote payload retrieval, persistence mechanism, or credential theft was identified in the audited file.

Attack Path

  1. The skill is loaded with its declared exec capability.
  2. The agent processes later untrusted or attacker-controlled content while the skill is active.
  3. Malicious instructions attempt to induce the agent to issue shell commands.
  4. Because exec was unnecessarily granted, those commands may run with the operating-system permissions of the hosting agent.
  5. The resulting impact depends on the host sandbox, user privileges, and command-approval controls.

This is a potential privilege-enablement path rather than evidence that the current skill actively performs exploitation.

Impact Assessment

Successful abuse could allow command execution within the permissions and sandbox boundaries of th ...[truncated 427 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the frontmatter and retain only capabilities required by the informational guide:

    yaml
    tools:
    - read
    
  2. Update the availability classification near lines 339–341 to describe the skill as Markdown-only rather than MD+EXEC.

  3. If command execution is added in a future version, document each required command and restrict execution through an explicit allowlist.

  4. Run commands in a sandbox with minimal filesystem and network access, non-privileged user permissions, and interactive approval for sensitive operations.

  5. Review tool permissions whenever skill functionality changes so that unused capabilities are removed.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description claims risky code was removed and external dependencies were cleaned up, which may reassure users, but the manifest still exposes exec capability. Claims of safety that conflict with actual privileges are dangerous because they can lower scrutiny and normalize over-privileged installation of the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed trigger keywords include generic terms like "informational," "guide," "automation," and "skill," which are common words in everyday requests and are not specific enough to narrowly scope invocation. The file also does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents the skill as an informational planning guide, but it also declares the exec tool, which expands the trust boundary from passive documentation to command-capable behavior. This mismatch can mislead users and host agents into granting unnecessary execution privileges, increasing the risk of unintended command execution or abuse if the skill is ever extended or interpreted operationally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

A skill with exec capability and natural-language task framing should clearly warn users that it can trigger command execution, but this file does not provide such disclosure. Missing warnings undermine informed consent and make it easier for users to treat a privileged skill as harmless reference material.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

  1. Flag customers with <50% of average usage
  2. Add flagged customers to "At Risk" segment in CRM
  3. Send re-engagement email campaign to at-risk customers
  4. Create task for me to personally reach out to top 10 at-risk customers
text

### Invoice and payment tracking

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes itself as Markdown guidance yet explicitly classifies itself as MD+EXEC and states that some functions require command execution capability. For a planning guide with no embedded executable workflow logic, this is unjustified privilege exposure and creates an avoidable opportunity for the agent to execute system commands based on natural-language prompting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

Substantial parts of the manifest description are written in Chinese while the rest of the skill is in English, and the file does not state that the skill is region-specific or let the user choose their preferred language. This can violate a language/locale policy when a skill implicitly forces or assumes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.