Back to skill

Security audit

Key Vault Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill claims to manage secrets but its scope and examples drift into unrelated review and scanning behavior while requesting read, write, and command execution access.

Review before installing. This skill may be intended as a key-management helper, but its instructions are inconsistent and request powerful local capabilities. Only use it in a constrained workspace, avoid giving it real secrets until the scope is clarified, and require explicit confirmation before any file write, command execution, API call, key rotation, sharing, or CI/CD injection.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s stated purpose conflicts sharply across sections: it presents itself as a key-vault manager, but the description also claims security auditing, vulnerability scanning, and generalized content review behavior. This kind of capability drift is dangerous because users and agents may invoke the skill under the wrong trust assumptions, causing inappropriate access to files, execution, or secrets under a misleading label.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation wording is overly broad and says to use the skill for vague security-related tasks rather than narrowly defined vault actions. Overbroad triggers are risky for a skill with read, write, and exec tools because they can cause the agent to invoke high-impact functionality in situations the user did not specifically authorize.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description explicitly says '支持中文交互' as part of the skill behavior, and the document is written to present Chinese interaction as the default mode without offering a language choice. This can violate language or locale policy when a skill forces a specific language absent user opt-in or a documented regional requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown advertises file writing, command execution, and external API interaction without a strong warning that these actions can change the local system state or transmit data. In the context of a purported secret-management skill, this is especially dangerous because users may expose sensitive keys to commands, files, logs, CI/CD systems, or remote services without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented response format is for grading and review output rather than vault-management operations, which indicates the skill may not do what its name and security framing claim. In a skill with read/write/exec access and secret-handling claims, mismatched outputs increase the risk of deceptive behavior, unsafe routing, or accidental disclosure during unrelated analysis tasks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples show a generic content-evaluation tool that scores submissions, not a key-vault manager. This mismatch is dangerous because examples guide real invocation behavior; users or agents may provide arbitrary content to a privileged skill that is simultaneously documented as managing secrets and executing commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.