Back to skill

Security audit

画板艺术工具专业版

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it asks for broad execution/write authority for team canvas publishing and governance while its triggers are too broad for that purpose.

Install only if you intend to use it for board-art batch publishing, animation, analytics, and governance. Before using it with real team boards, restrict API tokens to the minimum board and role scope, require explicit confirmation for publish/modify/delete/permission changes, and avoid invoking it for general analytics or automation tasks outside the canvas domain.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description and 'Use when' text are extremely broad, covering generic efficiency, automation, batch processing, and workflow optimization. This can cause the skill to be invoked for many unrelated user requests, increasing the chance that an MD+EXEC skill with read/write/exec capabilities is selected in contexts where its actions are unnecessary or risky.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The standalone trigger section says to use the skill whenever data analysis, reporting, statistics, or visualization are needed, which overlaps with many common agent tasks unrelated to this board-art domain. Because the skill exposes exec/write/read tools, broad invocation criteria materially raise the risk of accidental overreach and unsafe execution in the wrong context.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The description states '支持中文交互' in a way that presents Chinese interaction as a fixed operating mode, without clarifying that language should follow user preference. This can override user intent, reduce transparency, and in multilingual environments may cause misunderstanding of actions, prompts, or outputs before command execution.

Static analysis

No suspicious patterns detected.