Back to skill

Security audit

HTML 工具箱专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is an HTML/WCAG audit guide with disclosed command-line and network validation steps; broad routing language warrants caution, but no hidden or malicious behavior was found.

Install only if you want an agent to help audit local or authorized websites with HTML/WCAG tooling. Before use, confirm the target site is authorized, avoid passing secrets unless required for authenticated crawling, prefer environment variables for credentials, and treat the broad trigger wording as a documentation quality issue to tighten.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The skill presents itself as a Markdown-only HTML auditing tool, yet it explicitly enables command execution and outbound network use for crawlers and validators. That mismatch can cause operators or routing systems to grant broader execution and network privileges than expected, increasing the chance of unintended scanning or shell-capable behavior beyond the stated purpose.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The documentation is internally inconsistent: it claims to be pure Markdown with no extra operational requirements, while elsewhere describing authenticated crawling and command-driven external validation. Such contradictions can mislead users and automated policy systems into underestimating the privileges and external connectivity the skill actually uses.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The activation language is broad enough to match generic requests about security checks, compliance, quality inspection, encryption, automation, and analysis. Overbroad triggers increase the chance that an agent invokes this skill in contexts the user did not intend, potentially granting exec/networked audit behavior on unrelated tasks.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The coverage section lists ambiguous keywords rather than strict eligibility criteria, making it easier for an agent to select this skill opportunistically. In a skill with read/write/exec tools, ambiguous routing raises the risk of unnecessary file operations, command execution, or network scanning being triggered by loosely related prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.