Back to skill

Security audit

Baidu Netdisk Skills Free

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly describes a Baidu Netdisk helper, but its instructions also contain unrelated broad triggers and capabilities that could cause unsafe use outside that purpose.

Review carefully before installing. Use it only for explicit Baidu Netdisk tasks under /apps/bdpan/, and do not allow generic file-processing, Security-task, API-key, search, delete, rename, or backup behavior unless the publisher provides a corrected artifact with clear supported commands and auditable install/login scripts.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation advertises unsupported capabilities such as search, delete, rename, and backup even though the skill elsewhere says those operations are not available in the free version. This inconsistency can mislead an agent into invoking broader or riskier behaviors than intended, weakening safety boundaries and increasing the chance of unauthorized file operations.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill says it auto-activates for generic Security tasks, which directly contradicts the earlier Baidu Netdisk-specific trigger requirements. Overbroad activation criteria can cause the skill to run in unrelated contexts, exposing exec-capable behavior when the user did not intend to use this storage tool.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
Sections about API integration, API keys, HTTPS, and HTTP-style API failures conflict with the skill's stated CLI-only design. These contradictory instructions may prompt agents or users to introduce unnecessary secrets, external calls, or handling paths not actually required by the skill, expanding attack surface and causing unsafe configuration behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The top-level description tells the agent to use this skill for generic file processing, document conversion, format conversion, and content extraction, which is far beyond simple Baidu Netdisk file management. In an agentic environment with exec/read/write tools, this scope expansion can cause inappropriate activation and command execution in contexts unrelated to Netdisk operations.

Vague Triggers

High
Confidence
99% confidence
Finding
A trigger condition that auto-activates on generic security-related tasks is unrelated to the skill's actual domain and creates a severe scope-boundary failure. Because the skill exposes exec capability, ambiguous activation materially raises the risk of the tool being selected in inappropriate contexts and performing unintended local or remote file operations.

Static analysis

No suspicious patterns detected.