Back to skill

Security audit

代码

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it asks for broad command and file authority while its code-explanation purpose is inconsistent and under-scoped.

Review this carefully before installing. It may be useful as a code-assistance prompt, but its permissions and documentation are broader than a normal explain-code skill. Prefer installing only if you are comfortable granting shell and file-write authority, or ask the publisher to narrow the scope, remove exec/write, and align the output with code explanation.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a code-explanation tool, but its manifest expands scope into code review, project management, automation, and broader development assistance. This scope mismatch can cause agents or users to invoke the skill in contexts with higher privilege or different expectations than intended, increasing the risk of misuse and unsafe tool access.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documented output schema is an audit/scoring report rather than an explanation artifact, which materially changes the skill's effective behavior. This inconsistency can mislead orchestrators into trusting the skill for one task while it performs another, undermining safety assumptions and causing inappropriate automation decisions.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The FAQ and capability claims advertise code generation, bulk repository processing, and report export, which are substantially broader than simple code explanation. In practice, this can lead to overbroad invocation and higher-risk handling of large codebases or code modification tasks without corresponding guardrails.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
This skill declares exec capability despite being framed as a code-explanation tool, and the document does not justify why shell execution is necessary. Unnecessary command execution materially raises the attack surface because a loosely scoped skill could be induced to run commands, inspect the environment, or process untrusted inputs with system-level effects.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The request format says users provide code to explain, but the output format returns grades, scores, and compliance-style findings instead of an explanation. This input/output mismatch creates deceptive behavior that can be abused in automated pipelines, where agents may route sensitive code for explanation but receive policy judgments or other unintended processing.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance recommends use across broad development activities, including code generation, debugging, testing, and deployment, even though the skill is labeled as explanation-focused. Overbroad triggers increase the chance that an agent will invoke this skill in sensitive or high-impact workflows where its tools and behavior are not appropriately constrained.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description uses ambiguous activation language and mixes multiple workflow categories without clear boundaries. Ambiguity in when to invoke the skill can cause accidental activation in inappropriate contexts, especially in agentic systems that rely on textual matching for tool selection.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.