Back to skill

Security audit

云存储管理器(专业版)

Security checks for vulnerabilities and agentic risk

Overview

This cloud storage skill is mostly coherent, but it asks for powerful cloud and command-line authority while its activation scope and safety controls are too broad for automatic use.

Install only if you intend to use it for cloud storage administration. Before allowing it to run commands, require explicit user approval for migrations, bidirectional sync, lifecycle policies, KMS changes, and multi-replica writes; use cost estimates and dry-run or preview modes where available, and keep cloud credentials in a vault or environment variables.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The skill is presented as a cloud storage management tool, but the trigger text broadens usage into generic project management, task planning, and team collaboration. That scope drift can cause an agent to apply powerful filesystem, shell, and cloud-operation capabilities in contexts unrelated to storage administration, increasing the chance of unsafe or unauthorized actions.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document claims a cloud-storage management purpose but then instructs use for project management and progress tracking, which is inconsistent with the declared capability boundary. Conflicting instructions are dangerous because agents may resolve ambiguity by over-applying the skill in unintended domains while still retaining access to Bash, Read, Write, and Edit tools.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger language is broad and ambiguous, which can cause the agent to invoke the skill in situations far outside its safe operating envelope. In a skill that can drive command execution and cloud operations, ambiguous activation criteria materially increase the risk of accidental destructive changes, data movement, or misuse of credentials.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes high-impact capabilities such as bulk migration, bidirectional sync, lifecycle transitions, and multi-replica writes, but does not prominently warn about destructive outcomes like overwrite, propagation of deletion, storage-tier archival side effects, or large unexpected egress costs. In this context, missing safety warnings are dangerous because users and agents may execute irreversible or expensive operations without clear preconditions or confirmation.

Static analysis

No suspicious patterns detected.