Back to skill

Security audit

自适应设计偏好引擎

Security checks for vulnerabilities and agentic risk

Overview

This design-preference skill has a coherent purpose, but it asks for broad read, write, command, API, and callback capabilities without enough limits or user control.

Install only if you are comfortable with a skill that can build a lasting profile of your design preferences and may be granted read, write, command, API, and callback capabilities. Prefer using it in a sandbox with file and network restrictions, and review or disable automatic preference writes and callback URLs unless the publisher documents exactly what is stored and transmitted.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:24
Finding

Excessive Tool Permissions for a Preference-Learning Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-27
Additional Location: SKILL.md:332-336
Vulnerability Type: Excessive privilege and violation of least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

The skill declares unrestricted access to file-reading, file-writing, and command-execution tools. Its documented purpose is to learn and maintain visual design preferences, which does not require general system command execution. The document does not define command allowlists, filesystem path restrictions, approval requirements, or other enforceable boundaries around these capabilities.

Technical Analysis

Granting the exec tool creates a general local command-execution channel under the permissions of the hosting Agent process. The broad read and write declarations can likewise permit access to files unrelated to the visual-preference archive if the host does not impose separate sandbox controls.

This violates the principle of least privilege. A visual-preference skill should ordinarily require only access to a dedicated preference record or a narrowly scoped state-storage API. The documentation states that commands run in a sandbox, but it does not specify or enforce the sandbox policy in the skill configuration.

No malicious command, automatic exploitation behavior, credential theft, or persistence mechanism was found in the reviewed package. Exploitation therefore depends on the hosting Agent honoring these broad tool declarations and on malicious or misinterpreted input inducing tool use.

Attack Path

  1. A user or external content source provides a malicious design-related instruction containing prompt-injection content.
  2. The skill processes that content while the Agent has the declared read, write, and exec capabilities available.
  3. The injected instruction persuades the Agent to invoke a capability unrelated to visual-pre ...[truncated 1046 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the exec capability because no documented core workflow requires arbitrary command execution.
  2. Replace general read and write access with a dedicated preference-storage API where supported.
  3. If filesystem access is unavoidable, restrict it to one documented preference file or application-owned directory.
  4. Enforce canonical-path validation and reject traversal, symbolic-link escapes, and access outside the approved storage root.
  5. Require explicit user confirmation before reading or modifying any path outside the preference archive.
  6. Apply host-level sandboxing, minimal operating-system privileges, resource limits, and comprehensive tool-call audit logging.
  7. Define strict input validation so user-controlled design text cannot be interpreted as authorization for unrelated tool operations.
  8. Remove unsupported generic claims about command execution and file processing unless those capabilities are necessary and protected by enforceable controls.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says it will automatically observe user choices and feedback to build a lasting preference profile, but does not clearly warn users about data collection and persistence up front. That creates an informed-consent and privacy risk, especially because preference profiles may reveal sensitive behavioral patterns over time.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims it does not control design tools or render outputs, yet elsewhere advertises exec, file processing, and API integration capabilities. This mismatch can mislead users and reviewers about the real execution surface, increasing the chance that privileged actions are granted or invoked under false assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Callback URL support implies that data may be sent to external endpoints, yet the skill does not warn users about what information is transmitted or the trust boundary involved. This creates a plausible exfiltration path for user prompts, preference data, or derived metadata.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions direct the agent to persistently record and reuse user interaction data and preferences across sessions. Cross-session retention increases the risk of sensitive information leakage, unintended profiling, and later disclosure to unrelated tasks or users if storage boundaries are weak.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states that preference records are automatically confirmed and written after repeated signals, but does not explicitly warn that files or stored data will be modified. Silent persistence can surprise users and create unauthorized retention of personal preference data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to infer signals from user behavior and automatically write them into a preference archive after repeated interactions. Behavioral inference combined with persistence can capture more than users expect and may encode sensitive tastes, brand associations, or workflow habits that are later exposed or misused.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The usage steps explicitly tell the agent to monitor interactions, infer patterns, and save them for future outputs, establishing a durable profiling workflow. In the context of a skill with write capability and optional external callbacks, this persistence model becomes more dangerous because retained data may be modified, reused broadly, or transmitted outward.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s stated purpose is preference learning for design guidance, but it also advertises shell execution, file handling, and external API integration without a clear necessity boundary. Overbroad capabilities expand the attack surface and could be abused to access local data, alter files, or exfiltrate information unrelated to design preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file presents core metadata and instructions primarily in Chinese, with some English mixed in, but does not state that users may choose their preferred language. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy issue unless the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file declares both MD+EXEC and pure Markdown-only MD classifications, creating ambiguity about whether the skill can execute commands. This can cause unsafe deployment decisions, such as enabling shell access for a skill that reviewers thought was documentation-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.