Back to skill

Security audit

沟通助手专业版

Security checks across malware telemetry and agentic risk

Overview

This communication assistant is not clearly malicious, but it asks for broad agent powers and external integration behavior that are not well scoped or consistently disclosed.

Review this skill carefully before installing. It may be suitable only if you intentionally want an enterprise communication automation skill with shell/file access and external APIs enabled. Use it with least-privilege tools, avoid sensitive message content unless external transfer is acceptable, and require explicit confirmation before any API call, webhook notification, export, batch operation, or command execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The documentation gives conflicting safety guarantees: the FAQ says the tool will not send messages, while other sections describe API calls, webhook callbacks, cross-channel message handling, and automated execution. This mismatch can mislead users into exposing sensitive communication content under a false assumption that output is draft-only and never transmitted.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The manifest presents a narrow communication-assistant skill, but the body expands into generic automation, file processing, command execution, and multi-interface aggregation. That scope creep increases the chance an agent will invoke powerful tooling beyond user expectations, enabling unintended access to local files, shell capabilities, or external systems.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill advertises exec-style command capability in a context that does not clearly require shell access for a communication assistant. In agent environments with Bash, Read, Write, and Edit enabled, vague exec guidance can lead to over-privileged behavior, including local command execution and unintended system interaction.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation guidance says to use the skill broadly for AI model calls, intelligent dialogue, agent orchestration, and LLM applications, which is far wider than the named communication use case. Such open-ended triggering makes it easier for the agent to apply this skill in inappropriate contexts and activate higher-risk tools without clear task boundaries.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The scenario description relies on generic natural-language activation and says the tool will automatically execute corresponding operations. Without concrete constraints on permitted actions, that can cause users or upstream agents to trigger actions that exceed expected drafting or analysis behavior.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents API calls and webhook notifications but does not clearly and prominently warn that user-provided message content, metadata, or communication context may be transmitted to external services. In a communication-assistance skill, this is especially risky because inputs may contain sensitive interpersonal, customer, or business information.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.