Back to skill

Security audit

代码委派工具专业版

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it requests broad code-writing, command, file, and external API authority with loose boundaries, so users should review it before installation.

Install only if you are comfortable with an agent modifying code, running shell commands, writing local configuration/log files, and using external LLM/API services. Use it in a controlled workspace, review the global CLI dependency and generated config first, use least-privilege API keys, and avoid sensitive repositories unless external transmission and bulk changes are acceptable.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest markets the skill as providing workflow/configuration guidance, but the body clearly enables active capabilities through Read/Write/Edit/Bash tools, API use, and automated task execution. This mismatch can cause users or calling agents to invoke the skill under a lower-risk assumption, increasing the chance of unintended file modification, command execution, or data transmission.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The documentation expands into deployment steps, command execution, filesystem initialization, and external API operation even though the description frames the skill as guidance for code delegation workflows. That discrepancy weakens informed consent and can bypass policy expectations about what the skill is supposed to do.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The skill states it is not suitable for operations/deployment management, but the activation guidance immediately recommends using it for development deployment scenarios. Contradictory boundaries make it easier for an agent to apply the skill in a riskier context than intended, including deployment-time file writes and command execution.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation condition is overly broad, covering code generation, programming assistance, debugging, testing, and deployment with little specificity. Broad triggers increase the likelihood of accidental invocation in sensitive contexts where shell, file, or network actions may be inappropriate.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill includes commands that create directories and write configuration files, but it does not clearly warn users that local files will be modified. In an agent setting, undocumented state changes can affect repositories, tooling state, or audit artifacts without informed approval.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation instructs use of external APIs and API keys but does not clearly warn that prompts, code, or metadata may be transmitted to third-party services. This can expose sensitive source code or operational data if users assume the skill is local-only guidance.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.