Back to skill

Security audit

知识工具包(专业版)

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a knowledge-management helper, but it asks for broad file and command authority without clear workspace limits or user-control boundaries.

Install only if you are comfortable giving this skill file search/read authority and command execution for knowledge-management work. Use it with an explicit vault or project directory, avoid broad prompts like general automation requests, and confirm any batch import, export, callback, API, or command-running operation before proceeding.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill's activation guidance is tied to broad, common productivity requests such as improving efficiency, automation, workflow optimization, and batch processing. This can cause the skill to activate in many loosely related contexts and inherit access to powerful tools like read, glob, grep, exec, increasing the chance of unnecessary file access or command execution beyond a user's intended scope.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example invocation phrases are very generic and do not constrain the workspace, data sources, or permissible actions. In a skill with read/grep/glob/exec capabilities, vague prompts can lead the agent to operate over unintended files or take broader actions than the user expected, creating scope-creep and data exposure risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.