Back to skill

Security audit

DNS网络管理工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a DNS/network diagnostic helper, but its broad activation wording and executable network-probing examples need user review before installation.

Install only if you want an agent to run DNS, certificate, and connectivity commands on your behalf. Before use, restrict it to explicit network-diagnostic requests, avoid probing internal or production hosts without permission, and do not provide API keys unless a concrete command actually requires them.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
93% confidence
Finding
The skill advertises very broad activation guidance such as code generation, programming assistance, debugging, and deployment, even though its actual purpose is narrow DNS/network troubleshooting. Overbroad routing increases the chance the agent invokes a tool-enabled skill with exec/network capabilities in unrelated contexts, expanding attack surface and enabling unnecessary command execution or external probing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation includes commands that initiate outbound connections to remote hosts and retrieve certificate chains, but it does not clearly warn users that these actions contact external systems. In an agent setting with exec enabled, this can lead to unintended network access, information disclosure through observable probes, or policy violations if run against sensitive or internal targets.

Static analysis

No suspicious patterns detected.