Back to skill

Security audit

仪表盘

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a dashboard helper, but its instructions are inconsistent and request broad read/write/command authority without clear operational boundaries.

Review this skill before installing. It does not show clear malicious behavior, but it should be treated cautiously because it asks for broad agent tools while its documentation is inconsistent and not tightly limited to dashboard operations.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The documented response schema and workflow describe a generic scoring/evaluation tool rather than a dashboard for task queues, metrics, and ZeroTier status. This semantic mismatch can cause an agent or user to invoke the skill under false assumptions, potentially sending inappropriate data or granting broader trust to a capability it does not actually define.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The feature list expands the skill scope to generic file handling, API integration, command execution, and information retrieval beyond the stated dashboard purpose. Overbroad capability claims increase the chance of unintended or over-privileged use, especially because the manifest already exposes read/write/exec tools.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill is framed as an operations dashboard, but its input/output contract instead describes generic content processing and score generation. This inconsistency undermines reliable security review and may lead operators or agents to provide arbitrary content for processing, expanding the attack surface beyond the advertised function.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation guidance is broad and ambiguous, covering project management, planning, tracking, and collaboration without precise trigger boundaries. In an agent setting, this can cause over-invocation of a skill with exec/read/write permissions, increasing the chance of unnecessary command execution or data access.

Static analysis

No suspicious patterns detected.