Back to skill

Security audit

仪表盘工具箱

Security checks across malware telemetry and agentic risk

Overview

This dashboard skill is not malicious, but it asks for broad read/write/command authority for operational tasks without clear limits or user-confirmation rules.

Review this carefully before installing. It may be useful for operations monitoring, but only enable it in a constrained environment where command execution, file writes, API keys, cron changes, and deployment actions are explicitly approved and auditable.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims that only whitelisted commands are executed, but the document nowhere defines a whitelist, enforcement mechanism, or validation logic, while also advertising broad exec capability. This creates a misleading security assurance that could cause operators to trust unsafe command execution paths and increases the risk of arbitrary command execution through the skill.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The file states that sensitive fields are masked in logs, yet it also promotes execution logs and audit tracing without specifying any redaction rules, implementation details, or excluded data classes. This can lead users to assume secrets are protected when logs may still capture API keys, command arguments, outputs, or other sensitive operational data.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation and usage description is extremely broad, covering system monitoring, log analysis, alerting, deployment management, and workflow use without clear boundaries or safe-trigger conditions. In a skill with read, write, and exec permissions, vague scope increases the chance of over-invocation for sensitive tasks and can cause the agent to perform higher-risk operations without explicit user confirmation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises file handling, API integration, and command execution, but the description does not clearly warn users that it may write files or execute system commands. In an agent environment, missing consent and safety notice around these capabilities can lead to unexpected system modifications, unsafe command runs, or misuse of host resources.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.