Back to skill

Security audit

Jlc Eda Drawing

Security checks for vulnerabilities and agentic risk

Overview

The skill appears aimed at EasyEDA circuit automation, but it asks for command execution and bridge/API control while the referenced support files are missing and the activation scope is broad.

Review this skill before installing if you do not specifically need EasyEDA/JLC automation. Use it only in a controlled workspace with a known EasyEDA bridge setup, and avoid letting generic design-related prompts trigger command execution unexpectedly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims that risk code and unsafe dependencies were removed, yet it still explicitly declares the exec tool and directs the agent to use a bridge server script and API execution flow. This creates a trust mismatch: operators may lower scrutiny based on the safety claims while the skill still enables command execution and external process interaction, which materially increases attack surface.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are very broad (design, drawing, agent, advanced, etc.), making accidental activation more likely for unrelated tasks. In a skill that has exec capability and instructions to interact with a local bridge/server, overbroad invocation increases the chance the skill is selected in contexts where command execution or EDA automation was not intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file contains substantial Chinese-language instructions and metadata-like content embedded in an otherwise English skill description, but it does not state that the user can choose the language. This may force a locale/language experience without opt-in, which conflicts with the language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.