Back to skill

Security audit

谷歌字体工具专业版

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Google Fonts self-hosting and subsetting guide, but its trigger language reaches into unrelated security, encryption, and generic automation tasks while requesting command and file-write authority.

Install only if you intend to use it for Google Fonts self-hosting, subsetting, font licensing checks, and typography performance work. Treat unrelated security, encryption, or general automation claims as out of scope, and review any proposed shell commands before execution.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description and summary include extremely broad triggers such as '提升效率、自动化流程、批量处理、工作流优化' that are not specific to font management. In an agent ecosystem, this can cause the skill to activate for unrelated tasks while exposing powerful tools like exec and write, increasing the chance of unsafe or unintended command execution under the guise of a generic productivity request.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The explicit trigger section says the skill should be used for '安全检测、合规审计、质量检查、加密防护', which is mismatched with a font tooling skill. This ambiguity can route security- or encryption-related requests into a skill that also advertises exec capability, creating confusion, overreach, and potential misuse outside its intended domain.

Static analysis

No suspicious patterns detected.