Back to skill

Security audit

文档导航工具包(专业版)

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a documentation helper, but it asks for command execution and advertises broad write, export, API, and automation behavior without clear limits.

Review before installing. Use this only for trusted documentation folders, keep docs_root narrow, and require explicit confirmation before any command execution, package installation, file export, deletion, webhook/callback use, or API integration.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Intent-Code Divergence

Medium
Confidence
85% confidence
Finding
The skill is presented as a documentation-navigation tool, but later claims broader API integration and command execution capabilities without corresponding implementation details or guardrails. That capability inflation can cause an agent or user to over-trust the skill's authority to invoke external services or shell commands, increasing the chance of unsafe tool use in contexts where only read/search behavior was expected.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The description uses broad activation language such as productivity improvement, automation workflows, SEO optimization, and multiple generic scenarios, which can cause the skill to trigger for requests outside narrow document-navigation tasks. Over-broad matching is dangerous because it may route unrelated user requests into a skill that has exec, grep, glob, and read tools available, expanding the chance of unnecessary privileged actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises create/query/export operations and includes command-execution capability, but does not place strong, prominent user-facing warnings or approval gates around file writes and shell use. In a skill with exec and file access tools, ambiguous operational language can lead to destructive writes, unsafe exports, or execution of unintended commands when handling natural-language requests.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.