Back to skill

Security audit

项目管理API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a project-management API helper, but it requests broad local tool access and can change or send project data without enough scoping or user-control guidance.

Review this skill before installing in a workspace with real project data. Use a least-privilege API key, avoid untrusted callback URLs, and require the agent to ask before archiving, deleting, bulk-updating, or changing workflow state. The artifact does not show malware or hidden execution, but its local exec/write authority and weak mutation safeguards are broader than the API purpose needs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is vague and overbroad, describing flexible automation and multiple scenarios without clear boundaries on what the skill should or should not do. Ambiguous scope is dangerous for agentic systems because it increases the chance the model interprets user requests expansively and takes actions beyond intended project-management API operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises a GraphQL project-management integration but also requests exec, which materially expands its authority beyond what is needed for the stated purpose. This increases the blast radius of prompt misuse or downstream instruction injection, because a workflow that should only call an external API could instead run local shell commands on the agent host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The callback URL parameter enables sending results to an external endpoint, but the skill provides no privacy or trust warning about exfiltrating project data to third parties. In practice, a malicious or mistaken callback destination could receive sensitive issue contents, team metadata, comments, or identifiers without adequate user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents destructive actions such as updating state and archiving items without requiring confirmation or warning about irreversible or disruptive effects. In an agent context, that can lead to accidental modification of live project data, workflow disruption, or loss of visibility when a mistaken request is executed automatically.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation mixes a project-management API skill with unrelated file handling and command-execution troubleshooting, which can normalize broader behavior than users expect. That mismatch makes it easier for an agent or operator to justify unsafe local actions under the cover of an API integration, increasing the chance of unintended filesystem access or command execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.