Back to skill

Security audit

CSV转JSON工具

Security checks across malware telemetry and agentic risk

Overview

This skill looks like a CSV-to-JSON helper, but it asks for broad execution and file authority while describing unrelated API, command, and automation behavior.

Review this before installing. It may be harmless boilerplate, but the skill asks for execution and write authority and is described broadly enough to activate for API or automation tasks unrelated to CSV conversion. Prefer installing only if you trust the publisher and can constrain use to explicit CSV-to-JSON work.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as a narrow CSV-to-JSON converter, but later claims broader powers including file handling, API integration, command execution, and information retrieval. This capability mismatch can cause an agent or user to trust and invoke the skill in situations far beyond its stated purpose, increasing the chance of unsafe exec/write behavior being triggered under an innocuous label.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The document claims risk code and external dependencies were removed, yet the skill still advertises exec/write tools, API key handling, network-related failures, and command execution guidance. This creates a misleading safety signal that may lower operator scrutiny and encourage deployment of a skill with materially risky capabilities.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation language is broad enough to match many generic API integration, webhook, system connection, and automation requests, even though the nominal function is CSV-to-JSON conversion. Overbroad routing increases the likelihood that the skill is selected in inappropriate contexts where its exec/write permissions and ambiguous scope create unnecessary security exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.