Back to skill

Security audit

直播脚本生成免费版

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a livestream script-writing skill, but its broad triggers and shell/write permissions do not match that narrow purpose.

Review this skill before installing. It does not show malicious code or exfiltration, but its activation language should be narrowed to livestream script creation and its tool permissions should be reduced unless command execution and file writes are truly required.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
86% confidence
Finding
The trigger text is materially broader than the skill's stated purpose and can cause the agent to invoke this skill for unrelated analytics or generic workflow tasks. In a tool-enabled environment, overbroad routing increases the chance of unintended command use, incorrect handling of user data, or confusing the agent into performing actions outside the intended low-risk text-generation scope.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The manifest description includes broad activation language like efficiency, automation, batch processing, and workflow optimization, which can cause accidental invocation in many generic contexts unrelated to livestream scripting. Because the skill declares powerful tools, ambiguous activation expands the surface for unintended tool access and misuse even if the underlying content appears benign.

Static analysis

No suspicious patterns detected.