Back to skill

Security audit

知识管理工具(专业版)

Security checks for vulnerabilities and agentic risk

Overview

This knowledge-management skill is not malicious, but it asks for broad file, command, and integration authority while its scope and invocation text are inconsistent and under-defined.

Review this carefully before installing. Use it only on knowledge-management workspaces you intend the agent to inspect or modify, and require explicit confirmation before batch file changes, command execution, external API calls, callbacks, webhooks, scheduled jobs, or delete/modify operations.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest description claims the skill should be used for design, UI, posters, and brand visuals, while the rest of the file describes knowledge-management workflows. This kind of scope mismatch can cause the agent or user to invoke the skill in inappropriate contexts, increasing the chance of unintended file, command, or integration actions under false pretenses.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example prompts are broad enough to overlap with ordinary writing and planning requests, which can cause over-selection of this skill outside its intended domain. Because the skill advertises read/write/exec capabilities, ambiguous invocation increases the risk that powerful operations are triggered when a safer, narrower skill would have sufficed.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly advertises file writing, command execution, and external/API interactions, but the overview and usage sections do not foreground these as high-risk operations requiring caution. In an agent setting, underemphasized powerful capabilities can lead users or orchestration layers to approve or invoke the skill without understanding that it may modify files, run commands, or communicate externally.

Static analysis

No suspicious patterns detected.