Back to skill

Security audit

统一仪表盘基础版

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a dashboard/status helper, but its scope and privacy claims are too inconsistent for automatic trust.

Review before installing. Use it only for local dashboard/status tasks, avoid giving it broad analytics requests, and do not provide API keys or sensitive operational data unless the publisher clarifies which features contact external services and what data is sent or cached.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill claims data remains entirely local, yet later states that some features require network access to external APIs and API keys. This can cause users or agents to handle sensitive operational data under false privacy assumptions, potentially sending telemetry, prompts, or secrets off-host when they believed no external transmission would occur.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger condition says to use the skill for broad data analysis, reporting, statistics, and visualization tasks, which exceeds the stated scope of dashboard/task queue/system status operations. Overbroad invocation criteria can cause an agent to select this exec-capable skill in unrelated contexts, increasing the chance of unnecessary command execution, network access, or misuse against systems the user did not intend to touch.

Static analysis

No suspicious patterns detected.