Back to skill

Security audit

进化引擎

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local memory skill, but it should be reviewed because it requests shell execution while saying no shell execution is needed and it can create persistent conversation-derived records.

Review before installing. The skill is not showing exfiltration or destructive behavior, but users should be comfortable with persistent local memory in ~/evolution-engine/ and should remove or tightly scope exec access unless the publisher documents exactly why it is needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are broad terms such as reflection, learning, and self-improving that can match ordinary conversation. This can cause the skill to activate unexpectedly in unrelated contexts, leading to unsolicited persistent memory behavior and increased exposure to prompt-driven side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes persistent storage under ~/evolution-engine/ but does not provide a prominent warning or consent model before writing local files. Users may unknowingly cause long-lived storage of conversation-derived preferences, corrections, or project details, creating privacy and data governance risks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata exposes the exec tool while the documentation states the skill is pure Markdown and does not require exec. This mismatch can mislead users and reviewers about the skill’s actual capabilities, increasing the chance that an agent may invoke shell execution unnecessarily or that risky behavior escapes scrutiny.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The display name, summary, description, and trigger guidance are presented in Chinese, and the document does not indicate that language is selectable or that the skill is intentionally limited to Chinese-speaking users. This can conflict with language/locale policy expectations when a skill implicitly enforces one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.