Back to skill

Security audit

归档

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly documentation, but its stated purpose is inconsistent and it advertises scraping evasion plus broad file, API, and command abilities without clear user controls.

Review carefully before installing. Use only for clearly authorized targets and avoid enabling any scraping-evasion, cookie rotation, IP rotation, broad file writes, or command execution unless the user has explicitly approved the scope and data flow.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill description presents conflicting purposes: an archive/search/sync tool, but also guidance for SEO optimization and ranking improvement. This ambiguity can cause an agent or user to invoke the skill in contexts outside its actual safe scope, increasing the chance of unintended data access, misuse of external integrations, or execution of unsafe workflows.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill is presented as an archival tool, but its premium features include anti-bot evasion, adaptive crawling, and cookie/IP rotation. These capabilities materially change the risk profile by enabling stealthy web scraping and circumvention of access controls, while the benign branding may hide that behavior from reviewers or users.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation guidance is broad and vague, encouraging use whenever users need optimization or workflow help without precise boundaries. In an agent setting, such ambiguity can trigger the skill in inappropriate contexts, potentially leading to unnecessary command execution, external calls, or handling of sensitive data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises file handling, API integration, and command execution, but does not clearly warn users about side effects, security boundaries, or what actions may occur automatically. In an agent environment, this can mislead users into invoking operations that alter files, transmit data externally, or run commands without sufficiently informed consent.

Ssd 2

Medium
Confidence
97% confidence
Finding
Advertising anti-crawling evasion through wording like automatic bypass, adaptive page handling, and cookie/IP rotation signals deliberate support for defeating target protections. In context, this is more dangerous because the skill also exposes execution capability, making it easier to operationalize unauthorized scraping at scale while masking the activity as a normal archival feature.

Static analysis

No suspicious patterns detected.