Back to skill

Security audit

驱动

Security checks for vulnerabilities and agentic risk

Overview

This logo-design skill is not clearly malicious, but it asks for broad file and command authority that is not well scoped to brand-design output.

Review before installing. Use it only in a sandboxed workspace, avoid administrator privileges, do not provide sensitive brand or credential data, and require explicit confirmation before it reads files, writes outputs, calls external services, or runs any command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:12
Finding

Excessive Agent Capabilities and Unsafe Privilege-Elevation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares exec alongside read and write even though its stated purpose is logo and brand identity generation. This unnecessarily grants command-execution capability to a content-generation skill, increasing the chance that user-controlled prompts or future skill logic could invoke shell commands, access local resources, or pivot into broader system actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation wording is broad enough that an agent may activate the skill from loosely related conversation context rather than an explicit user request. Unintended activation becomes more dangerous here because the skill advertises read/write/exec-adjacent behavior elsewhere, so accidental routing could expose data or trigger side effects beyond simple design generation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest and top-level description present a narrow brand-design skill, but later sections expand it into generic file processing, API integration, and system command execution. This scope drift is dangerous because operators may authorize the skill based on a benign design use case while the documentation normalizes much broader capabilities that could be abused for data access, exfiltration, or arbitrary automation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The displayName is set to a Chinese term ('驱动') even though the rest of the file is mixed-language and there is no indication of user language preference or locale selection. This can violate language/locale policy expectations when a skill presents a fixed language choice without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file promises structured brand-identity outputs, but elsewhere frames the skill as a generic automation driver with broader operational features. This inconsistency can mislead users and reviewers about the true trust boundary, making it easier for high-risk capabilities to hide behind an apparently harmless design workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Colloquial follow-up phrases such as casual refinement requests are too generic and could be interpreted as implicit triggers for the skill outside a deliberate brand-design workflow. On their own they are low severity, but in combination with the skill's broadened capabilities they increase the chance of accidental invocation and confusing agent behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.