Back to skill

Security audit

字体管理器

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a font and typography guidance skill, but it includes unrelated project-management routing language while requesting command and write capabilities.

Review before installing. Use it only for typography and font-analysis work, and do not let the unrelated project-management wording broaden when the skill should run. Also verify whether the missing font-manager.py script is intentionally omitted or required for the advertised command-line features.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill is presented as a font-management/typography tool, but the capability coverage text also claims it should be used for project management, task planning, progress tracking, and team collaboration. This scope mismatch can cause an agent to invoke the skill in unrelated contexts, leading to inappropriate actions or user confusion about what the skill is authorized to do.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger/scope description is overly broad and includes unrelated usage contexts, which increases the chance that an agent will select this skill outside its intended domain. In agentic systems, overbroad routing language is dangerous because it can cause unintended tool invocation, expansion of effective permissions, and execution of local commands in workflows unrelated to typography.

Static analysis

No suspicious patterns detected.