Back to skill

Security audit

免费版

Security checks for vulnerabilities and agentic risk

Overview

This skill does not show malicious behavior, but its broad read/write/exec authority and vague, inconsistent AI automation instructions need review before installation.

Review this before installing. It appears to be a low-implementation markdown skill rather than a hidden payload, but it asks for broad agent tools and an API key while giving unclear boundaries and unsupported security assurances. Use only in a constrained environment and avoid providing sensitive data unless the actual platform encryption, storage, and command-execution controls are documented elsewhere.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
85% confidence
Finding
The documentation is internally inconsistent about whether the free edition supports SkillHub management. This can mislead users and agents about the skill's capabilities, causing incorrect invocation, unsafe assumptions about supported actions, and deployment mistakes in automation workflows.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The FAQ asserts encrypted transmission and storage guarantees, but the skill file contains no implementation or verifiable mechanism supporting that claim. Users may provide sensitive data under false security assumptions, leading to exposure if downstream tools, logs, or transport do not actually enforce encryption.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The invocation guidance is overly broad and suggests using the skill for generic AI model calls, orchestration, and dialogue tasks. In an agent ecosystem, this increases the chance of over-selection and unnecessary routing to a skill with exec/write capabilities, expanding attack surface and creating opportunities for unintended tool use.

Static analysis

No suspicious patterns detected.