Back to skill

Security audit

酷家乐AI室内设计

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a real Kujiale interior-design workflow, but it should be reviewed because it can read uploaded floorplan images, send them to a third-party service, use an account token, and its invocation scope is overbroad.

Review before installing. Use this only for Kujiale interior-design tasks, keep the token in a dedicated project folder, remove it when finished, and do not upload floorplans unless you are comfortable sending those images and derived design data to Kujiale. Confirm any quota-consuming layout or rendering step before allowing execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger condition 'user mentions interior design/renovation design' is broad enough to match many ordinary conversations, increasing the chance of unintended skill invocation. In this skill, accidental activation is more concerning because the documented flow can initiate external API calls, monitor local media directories, and eventually consume account quota on a third-party service.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description recommends use for broad categories like design creation, UI design, posters, and brand visuals, which greatly exceeds the actual interior-design function of the skill. Overbroad usage guidance can cause agents to route unrelated user prompts into this skill, leading to unexpected external processing or token-dependent operations outside the user's intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to monitor $HOME/.skill-platform/media/inbound for new uploaded images every 5 seconds, which implies automated access to local user-provided files without an explicit privacy notice, scope limit, or consent checkpoint. In agent environments, filesystem monitoring can expose more data than users expect and may normalize silent collection of uploaded content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
These steps direct the agent to upload user floorplan images and related design data to external Kujiale services, but the skill does not clearly warn users that their files and derived design artifacts will be transmitted to a third party. Because floorplans can reveal sensitive household layout information, undisclosed transfer to an external service creates a meaningful privacy and data-governance risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.