Back to skill

Security audit

消费级云存储-免费版

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a cloud-storage advice skill, but it requests command and file authority and includes unrelated automation/API/database language that does not fit its stated purpose.

Review before installing. The cloud-storage advice content itself is low risk, but the tool permissions and generic automation/API language are broader than the task requires. Prefer a version that removes exec/write access and narrows the description to consumer cloud-storage guidance only.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The manifest describes a simple consumer cloud-storage advisory skill, but the same description also claims unrelated database, SQL, and data-storage-management use cases. This scope confusion can cause an agent to invoke the skill in unintended contexts and grant it access to tools or data beyond what users would reasonably expect.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill explicitly says it is not for infrastructure/API scenarios, yet later advertises API integration, command execution, file processing, and full automation. These contradictory claims are dangerous because they normalize higher-risk behaviors and may lead the host agent to authorize unnecessary powerful actions under a low-risk advisory label.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The declared tools include exec, read, and write even though the stated function is only to recommend consumer cloud-storage services and explain common confusion. Overprivileged tool access increases the blast radius of prompt injection, misrouting, or future modifications, enabling filesystem or command-side effects where none should be needed.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Command execution is unjustified for a skill whose stated purpose is basic cloud-storage recommendations and conceptual clarification. In this context, exec materially increases the chance of arbitrary command abuse, environmental inspection, or chained compromise if the skill is triggered by adversarial content or misused by the agent.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
External API integration is not necessary for choosing between iCloud, Google Drive, Dropbox, and OneDrive or explaining synchronization concepts. Unneeded network/API capability expands the attack surface, risks data exfiltration, and undermines user expectations for a low-risk advisory skill.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
File write capability is excessive for a recommendation-and-explanation skill and creates unnecessary risk of local state changes, data corruption, or unauthorized file creation. Because the skill context is advisory-only, write access is more dangerous than in a file-management skill where such behavior would at least be expected and constrained.

Static analysis

No suspicious patterns detected.