Back to skill

Security audit

Cashu表情生成工具

Security checks across malware telemetry and agentic risk

Overview

The skill is framed as an emoji Cashu-token encoder, but it asks for broader execution, file, and API authority while underexplaining bearer-token and privacy risks.

Review this carefully before installing. Use it only with test or low-value tokens unless the publisher narrows the tool permissions, removes unnecessary exec/API requirements, and adds explicit Cashu bearer-token warnings. Do not assume emoji-hidden tokens are private or safe to share.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The skill is presented as a narrow Unicode/Cashu emoji encoder-decoder, but the documentation later advertises unrelated code review, dependency scanning, and CI/CD features. This scope mismatch can mislead users and agents into granting broader trust or invoking the skill in contexts far beyond its stated purpose, which increases the chance of unsafe execution paths being accepted without scrutiny.

Intent-Code Divergence

Low
Confidence
74% confidence
Finding
A local Unicode encoding/decoding utility should not normally require an LLM API, yet the documentation lists one as mandatory. This inconsistency can conceal unnecessary external data flow, causing users to expose inputs or tokens to third-party services when they expect an offline/local transformation tool.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The description claims that risky code and external dependencies were removed, but later sections explicitly describe command execution and API usage. Such contradictory safety claims are dangerous because they can reduce reviewer suspicion and encourage execution of a skill under false assumptions about its trust boundary.

Description-Behavior Mismatch

High
Confidence
93% confidence
Finding
The manifest frames the skill as a Unicode-based Cashu emoji encoder/decoder, but the documented behavior expands into file handling, external API access, and system command execution. This is a serious capability mismatch because an agent or user may authorize the skill for a harmless text transformation task while unknowingly exposing the host environment to much broader actions.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
Documented command execution is not justified by the stated function of hiding and extracting Cashu tokens in emoji. In skill ecosystems, any unnecessary exec capability materially raises the risk of host compromise, arbitrary command abuse, data exfiltration, or pivoting if the skill is invoked with untrusted input or overly broad permissions.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
External API integration is not necessary for a local Unicode transformation task, so its presence broadens the attack surface without clear justification. It creates additional risk of sensitive token disclosure, remote dependency abuse, and user confusion about where hidden-value data is processed.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The skill description uses broad, generic applicability language and weakly bounded use cases rather than clearly constraining what the skill should do. Overbroad framing is risky in agent environments because it can normalize inappropriate invocation, privilege creep, and use of the skill outside the narrow domain users think they are approving.

Missing User Warnings

High
Confidence
90% confidence
Finding
The skill promotes hiding transferable Cashu value inside emoji but does not clearly warn about privacy leakage, accidental disclosure, forwarding, logging, moderation bypass, or irreversible token transfer if the embedded token is exposed. Because the payload represents bearer value, understated safety guidance materially increases the chance of financial loss and covert misuse.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.