Back to skill

Security audit

DNS配置工具免费版

Security checks for vulnerabilities and agentic risk

Overview

This DNS helper is mostly instructional, but its routing text is much broader than DNS and it declares write capability without a clear need or confirmation boundary.

Review this skill before installing. It appears to be a Markdown DNS guidance skill, not malware, but its trigger language is too broad and could cause an agent to use it for unrelated coding or communications tasks. Only use it for DNS record lookup, TTL planning, email authentication records, and propagation checks, and require explicit confirmation before any DNS or file-changing action.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
79% confidence
Finding
The manifest frames the skill as a DNS helper, but the description broadens usage into generic messaging, notification, SMS, and communication integration. That scope drift can cause an agent to invoke this skill in unrelated contexts, increasing the chance of inappropriate tool use, user confusion, or unsafe actions outside the intended DNS domain.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger conditions are much broader than the DNS-specific purpose, saying the skill should be used for general code generation, programming assistance, debugging, and deployment. In an agent environment with exec/write access, overbroad routing criteria can cause this skill to be selected in inappropriate contexts, leading to unintended command execution or modification workflows unrelated to DNS.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The description's broad communication/notification wording overlaps with common high-frequency operational tasks that are unrelated to DNS. In a tool-routing setting, that can misdirect the agent into using a skill with exec/write capability for workflows the user did not intend, which enlarges the attack surface and raises the risk of accidental misuse.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill advertises create/modify/reset/import/export/save operations, and the manifest includes write capability, but it does not clearly warn users when actions may alter DNS-related state. In infrastructure contexts, silent or poorly signposted modification capability can lead to service disruption, mail delivery failure, or dangerous operator mistakes if an agent proceeds without explicit confirmation boundaries.

Static analysis

No suspicious patterns detected.