Back to skill

Security audit

首席创意官助手-免费版

Security checks for vulnerabilities and agentic risk

Overview

This creative-planning skill is mostly a text assistant, but it asks for command/file authority and describes broad automation that does not fit that purpose.

Review before installing. For normal creative brainstorming this skill should only need text generation, so avoid granting command execution, broad file write access, or external API access unless the publisher narrows and explains those capabilities.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is presented as a creative-planning assistant, but later sections advertise broad automation, file processing, API integration, and command execution. This scope expansion creates a misleading trust boundary: users may invoke the skill for harmless brainstorming while the platform grants capabilities that can affect files or execute system commands, increasing the risk of unintended or abusive actions.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Command execution is not justified for generating creative strategy text, yet the skill declares and documents exec capability. In this context, unnecessary execution privileges materially raise the attack surface because prompt-induced behavior, misuse, or future workflow changes could turn a benign ideation skill into a system-impacting one.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The documented read/write and external API integration capabilities exceed what is needed for a creative text assistant and are not clearly bounded. Unnecessary file modification and outbound communication capabilities can expose local data, alter workspace state, or facilitate unintended data transfer if the skill is invoked broadly.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The documentation says the skill only outputs text guidance, but later sections claim automation, file, API, and command-execution behavior. This contradiction is dangerous because it can mislead users and reviewers about the real operational authority of the skill, causing underestimation of risk and insufficient safeguards.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation condition is extremely broad, effectively suggesting use whenever AI models, orchestration, or LLM applications are involved. This can cause the skill to be selected in unrelated contexts where its declared tools and expanded capabilities are inappropriate, increasing the chance of accidental misuse or exposure to sensitive workflows.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The usage instructions rely on generic natural-language requests and do not define boundaries for what the skill should refuse or when higher-risk capabilities would be used. In a skill with read/write/exec available, vague triggers make accidental overreach more likely because users may assume any loosely related request is in scope.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The capability description mentions file writing, API usage, and command execution without prominently warning about their effect on data or system state at the point those capabilities are described. For a user expecting a creative assistant, this lack of contextual warning can lead to uninformed consent and unsafe invocation of high-impact tooling.

Static analysis

No suspicious patterns detected.