Back to skill

Security audit

JSON验证工具

Security checks for vulnerabilities and agentic risk

Overview

The skill does not show malicious behavior, but it asks for broad command, file, API, and credential-related authority for a loosely defined JSON validation purpose.

Review this skill carefully before installing. Use it only with non-sensitive JSON unless the publisher clarifies the Expanso Edge service, exact API endpoint and data handling, allowed commands, file write locations, and whether explicit user confirmation is required before external calls or command execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill claims it has removed risky code and external dependencies, yet the same document explicitly requires an API key, supports exec, and describes external/API-driven behavior. This is dangerous because it creates a misleading trust signal that can cause users or agents to authorize command execution and data transmission under false assumptions about safety and isolation.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill is presented as a narrow JSON validation tool, but the description expands into broad integration, automation, synchronization, visualization, and operational capabilities. This mismatch is dangerous because users may grant the skill more trust, data access, and execution scope than warranted, increasing the chance of unexpected command execution or data handling beyond JSON validation.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is broad and vague, describing many generic integration and workflow scenarios without clear trigger boundaries. In an agent setting, ambiguous scope increases the likelihood that the skill is selected inappropriately for tasks involving sensitive files, credentials, or system operations, leading to unnecessary exposure and unintended side effects.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The document references API key configuration, execute()-style operation, command execution, and file/result handling, but does not provide a prominent user-facing warning that data may leave the local environment or that actions may have side effects. This is dangerous because users may submit sensitive JSON, credentials, or local file content without understanding that the skill can execute commands and interact with external services.

Static analysis

No suspicious patterns detected.