Back to skill

Security audit

结构化开发工具专业版

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate-looking development workflow skill, but it is broad enough to run file, shell, API, and release/deployment actions without clear user gating.

Install only if you want an agentic development workflow skill that may modify project files, run shell commands, use API credentials, create local audit/config files, and assist with release workflows. Before use, require explicit confirmation for writes, shell commands, network/API calls, callbacks, tags, changelog changes, and any staging or production release action.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger condition is so broad that the skill can auto-activate for generic user requests related to 'relevant tasks,' while the skill has access to Read/Write/Edit/Bash and discusses API/network operations. Over-broad invocation increases the chance that high-impact file, command, or release actions are introduced into ordinary conversations without sufficiently explicit user intent.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description says to use the skill broadly for code generation, programming assistance, debugging, testing, and deployment, which overlaps with many common developer prompts. In a skill with Bash, file-write, and external-service capabilities, vague invocation guidance can cause the agent to select the skill in situations where the user expected only advice, creating avoidable risk of impactful actions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly advertises API integration, file handling, and command execution, and elsewhere includes release-management and environment-changing workflows, but it does not present a prominent user-facing warning that these actions can modify files, execute shell commands, contact external services, or affect deployments. In this context, missing impact disclosure is dangerous because users may invoke the skill expecting passive guidance while it is positioned to perform state-changing operations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.