Back to skill

Security audit

能力扩展工具专业版

Security checks across malware telemetry and agentic risk

Overview

This skill is a review item because it asks for broad data-source, credential, caching, and team-sharing access while its activation language is partly mismatched and too broad.

Install only if you intend to let the agent query configured internal or external knowledge sources and write local or team-shared caches. Use narrowly scoped tokens, avoid putting secrets or sensitive project details in prompts, and confirm where cached or shared results are stored before enabling team sharing or prefetching.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest describes a cheat-code/development helper, but the skill content actually centers on enterprise knowledge retrieval, external data-source access, caching, and team sharing. This scope mismatch can cause an agent or user to invoke the skill under false assumptions, leading to unnecessary credential use, network access, and data handling beyond the user's intended task.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The documented capabilities focus on bulk external querying, custom data sources, caching, prefetching, and team knowledge-base operations rather than code generation or debugging. This discrepancy increases the risk of over-privileged activation, where a development-oriented request silently expands into broader data collection and persistence behaviors.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Team-shared knowledge-base creation and persistence are materially broader than what a generic cheat-code or development workflow helper would need. In context, this creates avoidable risk of retaining and redistributing potentially sensitive prompts, results, or internal technical information to other users or systems.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill instructs configuration of multiple external-service credentials through environment variables despite being presented as a generic development helper. That broadens the trust boundary and may prompt users to provision sensitive tokens to a skill whose actual scope was not transparently described.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation guidance is overly broad, recommending use for general code generation, debugging, testing, and deployment despite the skill's actual emphasis on external knowledge retrieval and integration workflows. Over-broad triggers increase the chance that the skill is invoked in contexts where it gains unnecessary access to files, shell, networked systems, or credentials.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes local cache directories and shared storage behavior without prominently warning users that content may be written to disk and persisted for later reuse. In this context, users may unknowingly store proprietary queries, internal documentation references, or sensitive outputs on the local filesystem or in shared team locations.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill encourages querying internal and external data sources but does not clearly warn that user prompts and related metadata may be transmitted to third-party or enterprise services. In a knowledge-retrieval context, this is dangerous because prompts may contain confidential project details, security issues, credentials, or internal architecture information.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.