Back to skill

Security audit

表情符号工具箱(专业版)

Security checks across malware telemetry and agentic risk

Overview

This documentation-only skill openly teaches encrypted hidden emoji messaging and detection-avoidance tactics, so it should be reviewed before installation.

Install only if you have an authorized, legitimate need for hidden-message analysis or controlled watermarking. Treat it as a high-risk covert-communications tool: avoid using it to bypass monitoring or platform rules, review any commands before execution, limit file access to intended inputs/outputs, and understand that token verification, transport checks, reports, caches, and watermark libraries may create local or network-visible records.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill claims all encoding/decoding is local and implies message content is not sent externally, yet elsewhere documents network-dependent transport testing and token verification against external servers. This can mislead users about data exposure boundaries and create unsafe assumptions when handling sensitive or covert communications.

Intent-Code Divergence

Low
Confidence
87% confidence
Finding
The documentation says no extra API keys are needed while also listing an LLM API dependency and external network-backed functions. Even if keys are platform-managed, this is still materially misleading because users may believe the skill is self-contained and offline-safe when it is not.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation enables automatic watermark embedding and specifies a local library path without warning that user content may be modified or that watermark data may be written to disk. In an agent skill context, this can lead to silent alteration of user-generated content, privacy issues, and unexpected persistent file writes, especially if users assume the tool is read-only or transformation-only.

Ssd 4

Medium
Confidence
95% confidence
Finding
The skill presents a structured covert-communication workflow centered on hiding, encrypting, transmitting, validating, and tracing secret messages. In context, this is not a neutral encoding utility; it operationalizes clandestine communication and lowers the barrier to abuse for evasion of monitoring or policy controls.

Ssd 4

High
Confidence
98% confidence
Finding
The custom encoding section explicitly advertises anti-detection and high-concealment scenarios through alternate mappings and multilayer encoding. That is directly useful for evading inspection and detection systems, making the skill materially more dangerous than a generic text encoding tool.

Ssd 4

High
Confidence
97% confidence
Finding
The carrier-selection strategy is designed to make hidden messages blend into normal conversation and resist pattern/statistical analysis. This is explicit evasion guidance that improves stealth and detection resistance, increasing the offensive utility of the skill.

Ssd 4

High
Confidence
96% confidence
Finding
The documented workflow gives a practical recipe for covertly preparing, encoding, encrypting, transmitting, and auditing sensitive messages across compatible channels. Stepwise operational guidance meaningfully facilitates misuse by helping users deploy hidden communications reliably and at scale.

Ssd 4

Medium
Confidence
93% confidence
Finding
Repeated claims that custom encoding and auto-selection help avoid detection and avoid attracting attention reinforce an evasion-focused use case. Even as documentation, this normalizes stealth behavior and teaches users how to improve clandestine communications.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.