Back to skill

Security audit

CSV转JSON工具

Security checks across malware telemetry and agentic risk

Overview

This skill mostly describes CSV-to-JSON conversion, but it also asks for broad execution, file, API-key, and integration behavior that is not clearly scoped to that purpose.

Review this before installing. It has no executable files, but its instructions request read, write, and exec authority and discuss API credentials, network/API calls, and command execution. Only use it in an environment where you are comfortable granting those capabilities, or narrow it to explicit CSV-to-JSON conversion with no API-key or command-execution workflow.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as a narrow CSV-to-JSON converter, but the description broadens its purpose to generic API integration, webhook/system connectivity, and automation workflows. That scope expansion can mislead users and agents into granting broader trust, permissions, or execution paths than expected, increasing the chance of unsafe command or network use under an innocuous label.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The later sections describe API-key-based operation, network communication, and command execution as normal usage, which materially conflicts with the advertised CSV conversion function. This mismatch is dangerous because reviewers or agents may approve the skill for simple data transformation while it actually expects privileged external access and execution capabilities.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document claims that risky code and external dependencies were removed, yet later content still describes command execution, network communication, and API-key-dependent behavior. This creates a false sense of safety and may cause users or automated reviewers to lower scrutiny around a skill that still has materially risky operational characteristics.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is broad enough to cover general API integration, system connection, and workflow tasks rather than a tightly scoped CSV-to-JSON operation. Overbroad triggers can cause the skill to activate in contexts where users did not intend to grant file, execution, or integration behavior, increasing the risk of unintended privileged actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.