Back to skill

Security audit

自动驾驶流程

Security checks for vulnerabilities and agentic risk

Overview

This automation skill is coherent and not malicious, but it needs review because it encourages agents to build automation proactively with exec, cron, file movement, and integrations without a clear approval boundary.

Install only if you are comfortable with an agent proposing and potentially creating automation. Before allowing it to act, require explicit approval for every script write, command execution, cron job, resident watcher, external API call, email send, and file move; start with dry-run or test directories and keep a clear disable/removal path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:46
Finding

Unauthorized Automation Through Skill Instruction Hijacking

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly encourages the agent to act on broad repetition cues such as '看到重复立刻构建' rather than waiting for explicit user authorization. In a skill with exec capability, this can cause the agent to initiate automation design or execution for impactful operations without sufficiently bounded consent, increasing the risk of unintended file changes, scheduled jobs, or external actions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords include very generic everyday terms like '自动化', '周报', '数据清洗', and '文件整理', which can cause accidental invocation in ordinary conversations. Because the skill also promotes proactive automation behavior, generic triggers expand the chance that the agent shifts from discussion into operational assistance in contexts where the user did not intend that level of action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The text tells the agent to '直接做' and emphasizes not waiting for user requests, while the skill exposes exec and describes scripts, cron, file operations, and external integrations. Without prominent warnings and confirmation requirements, this creates a realistic path to impactful actions being proposed or performed before the user understands the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file-organization template describes monitoring the Downloads folder and moving files based on rules, but it does not prominently warn about misclassification, destructive reorganization, or interference with user workflows. In an exec-enabled environment, even a well-meant automation can cause data loss-like outcomes, confusion, or operational disruption if files are moved unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.