Back to skill

Security audit

DNS查询工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a DNS lookup helper, but it asks for broad read/write/command authority and contains unrelated API, file-processing, and marketing-workflow guidance that users should review before installing.

Install only if you are comfortable granting a DNS helper read/write/command capabilities. Treat it as a review item: restrict use to explicit DNS lookups, avoid setting a generic API_KEY for it, and do not let it perform unrelated file, API, or shell tasks without direct confirmation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The skill is presented as a DNS lookup utility, but later claims generic file processing, API integration, information retrieval, and command execution capabilities. This scope expansion can mislead an agent or user into granting broader trust and permissions than needed, increasing the chance of unintended file, network, or shell actions outside the expected DNS-only behavior.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The document mixes a simple dig-based local DNS utility with instructions to configure a generic API_KEY, creating ambiguity about whether external services or authenticated APIs are involved. This can cause users or agents to expose secrets unnecessarily or assume trust boundaries that do not actually apply to a DNS lookup tool.

Vague Triggers

High
Confidence
92% confidence
Finding
The usage trigger includes broad, unrelated business scenarios such as marketing, advertising, conversion, and growth workflows, far beyond DNS resolution. Overbroad triggers increase the likelihood that an agent invokes this skill in inappropriate contexts, exposing exec/write/network capabilities when the user did not request a DNS operation.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises file write, command execution, and external/API behavior without clearly warning that these actions may modify files, run shell commands, or contact external systems. In an agent setting, this can lead users to treat the skill as a harmless lookup tool while it has materially broader side effects and authority.

Static analysis

No suspicious patterns detected.