Back to skill

Security audit

知识捕获工具(专业版)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a knowledge-capture helper, but it asks for broad file and command authority while giving vague triggers and unclear controls for saving or exporting conversation content.

Review before installing. Use this only when you deliberately want conversation or meeting content turned into stored notes, and confirm where the output will be written or exported. Avoid using it on sensitive chats unless you control the destination, and do not rely on its sandbox, encryption, audit, or whitelist claims without platform-level enforcement.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill advertises that commands run in a '安全沙箱' but the file only declares the `exec` tool and provides no technical control, policy, or wrapper that enforces sandboxing. This can mislead users or downstream agents into treating command execution as safe and may result in arbitrary local command execution with the agent's real privileges.

Vague Triggers

High
Confidence
93% confidence
Finding
The activation text is overly broad, covering generic productivity, automation, batch processing, and workflow optimization requests. In an agent ecosystem, this can cause the skill to trigger in unrelated contexts and gain access to sensitive conversation content or file operations without the user making an informed, specific choice.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example triggers are very short and ambiguous, such as extracting knowledge points or generating minutes without clarifying storage, data scope, or destination. This increases the chance that an agent invokes the skill on sensitive conversations or archives content unexpectedly.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill emphasizes automatic classification and saving to knowledge bases or local documents but does not provide a clear user warning that conversation content may be persisted outside the immediate session. This creates a meaningful privacy and data-handling risk because users may supply sensitive chats, meeting notes, or internal discussions without realizing they can be stored or exported.

Static analysis

No suspicious patterns detected.