Back to skill

Security audit

画板艺术工具

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a canvas pixel-art publishing helper, but its broad activation wording and state-changing command guidance make it need review before installation.

Install only if you intend to use it for the specific shared-canvas pixel-art workflow. Review or narrow its trigger text first, confirm any publish/delete action before execution, and provide only a scoped canvas service token through the environment.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a narrowly scoped canvas art publishing tool, but its documented core capabilities expand into generic create/query/modify/delete/import/export/configuration operations. This mismatch weakens least-privilege expectations and can cause an agent or user to authorize broader actions than the advertised domain warrants, increasing the chance of misuse or unsafe tool invocation.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The manifest markets the skill for broad efficiency, automation, batch processing, and workflow optimization, while the body later states the free version cannot batch publish multiple works. This inconsistency can cause inappropriate routing of unrelated tasks into a skill with exec/write capabilities, making accidental overreach more likely.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The error-handling section recommends generic network diagnostics such as running ping and broader connectivity troubleshooting, which are not necessary to describe a canvas publishing skill's functional scope. In a skill that already permits exec and write, this normalizes out-of-domain command execution and expands the operational envelope beyond the stated purpose.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The documentation explicitly says the free edition cannot batch publish, yet the manifest advertises batch-processing support. Conflicting capability statements can mislead selection logic and users into invoking the skill for broader automated tasks than intended, which is especially risky given the presence of exec/write tools.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description uses very broad trigger language such as efficiency improvement, automation, batch processing, and workflow optimization, which overlaps with many unrelated user requests. Over-broad routing is dangerous because it can cause an agent to activate a skill with exec/read/write capabilities outside its intended canvas-art domain.

Vague Triggers

High
Confidence
98% confidence
Finding
The declared trigger conditions reference project management, task planning, progress tracking, and team collaboration, which are unrelated to a personal canvas art publishing utility. This mismatch makes the skill much more dangerous in context because it invites activation during common business workflows despite carrying execution and file-write capability.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill documents modify/delete-capable operations in a generic way but does not foreground a clear warning that these actions can change or remove board content and exported data. In context, this can lead users or agents to treat the skill as informational when it is actually state-changing, increasing the risk of unintended destructive actions.

Static analysis

No suspicious patterns detected.