Back to skill

Security audit

文件RAG

Security checks for vulnerabilities and agentic risk

Overview

This file-RAG skill is not clearly malicious, but it asks for broad file and command authority while making inconsistent claims about local-only operation, external API use, security features, and collaboration.

Install only if you are comfortable granting an agent broad local file access and possible command execution for document processing. Keep it away from secrets or sensitive directories unless you can enforce sandboxing, review every proposed write or command, and confirm whether any API calls send file content outside your machine.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is broad and vague for file-related tasks, which increases the chance that the skill is invoked in situations involving sensitive files or high-impact system operations without clear scoping. In a skill that advertises read, write, and exec tools, ambiguous triggers materially raise the risk of unsafe use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes file operations, command execution, and API integration without an upfront warning about their potential effects on the local system or data exposure. Given the declared availability of read, write, and exec tools, lack of prominent safety disclosure can lead users to authorize actions with significant system, privacy, or integrity impact without understanding the risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states the skill is local-only, yet elsewhere declares an LLM API dependency and includes network-related error handling and API integration language. This inconsistency can mislead users into exposing data to external services they did not expect, undermining informed consent and security assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The FAQ claims the skill provides encryption and permission management, but no such capability is described in the actual interface, dependencies, or operation details. Users may rely on nonexistent protections for sensitive files, increasing the chance of data exposure or misuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims to support team collaboration while also stating it is local-only and does not support multi-device sync. Contradictory capability claims can cause users to adopt the skill for collaborative handling of data without understanding its real constraints, creating operational mistakes and possible accidental data sharing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.