Back to skill

Security audit

CSS避坑指南

Security checks for vulnerabilities and agentic risk

Overview

This CSS guide is a single Markdown skill, but it asks for broad command and file permissions that are not well scoped to CSS help.

Review this before installing. The CSS advice content is ordinary, but the permission and capability claims are much broader than needed. Prefer a version that removes exec/write access and generic API or callback behavior, or install only in an environment where those capabilities are blocked or require explicit confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Granting command execution to a CSS pitfall guidance skill is unnecessary and materially dangerous because it enables shell access in a context where users expect static advice only. If the agent routes requests to this skill automatically, an attacker could exploit the over-privileged toolset to run local commands unrelated to CSS troubleshooting.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation language is broad and repetitive, effectively saying to use the skill whenever the user needs CSS-related help, without narrowing to specific tasks or exclusions. Overly broad invocation criteria increase the chance of accidental routing into an over-privileged skill, which is more dangerous here because the skill also declares exec and file access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description states "支持中文交互" as a capability, and the displayed name/content consistently frame the skill around Chinese-only interaction without offering a language choice. This may violate language/locale policy when a skill implicitly forces a specific language rather than letting the user opt in or choose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a CSS guidance/reference skill, but its manifest also declares broad execution, file I/O, and workflow capabilities unrelated to that purpose. This capability mismatch increases attack surface and can mislead an agent into granting or invoking privileged actions that are unnecessary for answering CSS advice questions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file contains contradictory statements about whether the skill is pure Markdown or uses execution tooling, which creates ambiguity about its actual privileges. Ambiguity in security-relevant documentation is dangerous because agents and users cannot reliably predict whether invoking the skill may trigger privileged actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Advertising file read/write processing for a CSS advice skill expands the perceived scope from advisory output to direct filesystem interaction. In an agent environment, that mismatch can prompt unsafe access to local project files or enable modification workflows users did not intend when invoking a simple guidance skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation advertises API integration and network-style behavior that is not justified by the stated CSS guidance function. Even if not directly implemented here, normalizing such behavior can cause agents or operators to treat external communication as expected, increasing the risk of data exfiltration or unsafe tool invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.