Back to skill

Security audit

JSON修复工具免费版

Security checks across malware telemetry and agentic risk

Overview

The skill appears intended for local JSON repair, but its instructions are broad and inconsistent enough that users should review it before installing.

Install only if you intend to use it for explicit, user-directed JSON repair tasks. Review file paths before allowing execution, expect local .bak files and possible overwrites, and avoid letting the skill handle unrelated API, networking, deployment, or general agent-orchestration work unless the publisher narrows the instructions.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill documentation presents the tool as local-only and not dependent on external services, but elsewhere introduces LLM API dependence, network diagnostics, HTTPS guidance, and API integration. This inconsistency can cause an agent or operator to grant broader permissions or make incorrect trust decisions about data flow and execution scope.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is advertised as a narrow JSON repair utility, but later claims generic file handling, API integration, and command execution capabilities. In an agent ecosystem, this kind of scope expansion can cause over-invocation, excessive permissions, and unsafe use outside the user's intended task.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Network/API integration is not justified by the stated function of local JSON syntax repair, yet the skill includes language encouraging network connectivity checks and external API concepts. This broadens the apparent operational surface and may lead agents to perform unnecessary network-related actions or expose local data beyond the expected local-only context.

Vague Triggers

High
Confidence
96% confidence
Finding
The invocation language is overly broad, stating the skill should be used for AI model calling, intelligent dialogue, agent orchestration, and LLM applications generally. In an automated skill-selection system, this can cause the skill to match many unrelated tasks and unnecessarily introduce exec/read capabilities into workflows that did not need them.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The coverage keywords include many generic phrases such as code generation, deployment, workflow automation, and broad development assistance without tight constraints. This increases the chance that an agent router will select this skill in inappropriate contexts, expanding access to read/exec beyond the intended JSON-fix use case.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.