Back to skill

Security audit

结构化开发工具免费版

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a local coding-workflow guide, but its instructions conflict about execution, network/API use, and credential handling, so users should review it before installing.

Install only if you are comfortable with a coding assistant that can read, write, search, and execute commands in your project. Treat its API key, credential, callback, and network sections as inconsistent with the claimed local-only boundary, and require explicit approval before any command execution, network call, deployment, or credential use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Confidence
94% confidence
Finding
The skill states in its safety boundary that it does not automatically execute code, but later advertises '自动化执行' and command execution capabilities. This inconsistency can mislead users and the hosting agent about the skill's behavior, increasing the chance that code or shell commands are run with less scrutiny than warranted.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The privacy/security section claims the tool does not make network requests and keeps data local, but other sections describe API integration, external service calls, TLS communication, API key configuration, and credential-based connection setup. Such contradictions can cause sensitive data to be exposed to external systems when users or agents believe the tool is offline-only.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation guidance says to use the skill broadly for code generation, programming assistance, debugging, testing, and deployment whenever related needs arise. Overly broad routing increases the likelihood that this powerful skill—with read/exec/write/glob/grep capabilities—will be invoked in situations where a narrower, safer skill would be more appropriate.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.