Back to skill

Security audit

图谱

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a blockchain Graph Protocol helper, but it requests broad read/execute/write authority while its instructions are inconsistent and under-scoped.

Review this skill carefully before installing. It may be useful for blockchain Graph Protocol routing, but its requested read/execute/write authority and generic API key setup are broader than the documented task. Install only if you can constrain tool access and are comfortable with ambiguous instructions around command execution and non-blockchain analytics use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The declared JSON return format describes a grading/audit report with fields like overall_grade, code style, and security compliance, which conflicts with the stated purpose of routing blockchain data questions to Graph Protocol services. This semantic mismatch can mislead an agent into invoking the skill under false assumptions, causing incorrect downstream automation, unsafe trust decisions, or improper handling of user requests.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The functionality section claims generic capabilities such as Chinese interaction and workflow-related abilities that do not clearly map to the blockchain-routing purpose. Overstated or conflicting capability claims increase the chance that an agent routes unrelated tasks to this skill, creating prompt-scope confusion and potentially exposing data or triggering tools in contexts the skill was not designed for.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation description is excessively broad, saying to use the skill for data analysis, reporting, statistical insights, and visualization, while the core function is supposedly routing blockchain data questions to Graph Protocol services. Ambiguous trigger conditions can cause over-invocation, inappropriate tool access, and accidental processing of requests outside intended scope.

Static analysis

No suspicious patterns detected.