Back to skill

Security audit

Logo品牌设计工具

Security checks across malware telemetry and agentic risk

Overview

This logo skill is not clearly malicious, but it asks for broad read/write/command authority while its documentation mixes logo generation with unrelated automation, code, ops, and API capabilities.

Review before installing. Use this only if you are comfortable granting a logo skill broad read, write, and command-execution authority, and avoid invoking it for operations, code, deployment, or bulk file tasks unless the publisher narrows and documents those capabilities.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill is presented as a logo-generation tool, but this section advertises unrelated code analysis, dependency scanning, and CI/CD capabilities. That mismatch can mislead an agent or user into granting broader trust and invoking the skill in contexts far beyond its stated purpose, increasing the risk of unintended execution paths and over-privileged use.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documented contract is generic content-processing output with a 'reviewer' template rather than a logo-design interface. This inconsistency makes it unclear what the skill really does and can cause downstream agents to pass arbitrary content or interpret outputs incorrectly, which is dangerous when the skill also declares write and exec tooling.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
This section expands the skill from logo design into file handling, external API use, and system command execution. Broad operational claims combined with tool access create a materially larger attack surface because an agent may authorize sensitive filesystem or shell actions under the guise of a creative design skill.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest description mixes logo design with operations monitoring, log analysis, alerting, and deployment management. This is a severe scope-confusion issue: the skill’s identity no longer matches its use cases, so agents may invoke it in sensitive operational contexts where a creative skill should never apply.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
These sections redefine the skill as a generic automation and execution tool rather than a narrowly scoped logo assistant. In context, that broadening is especially dangerous because the skill declares read/write/exec tools, so ambiguous positioning can normalize use in high-risk tasks without adequate scrutiny.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description is overly broad and ambiguous, spanning multiple unrelated domains. Ambiguous trigger scope increases the chance that an agent auto-selects this skill for inappropriate tasks, which is risky given the presence of powerful tools and unclear operational boundaries.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The quick-start tells users to invoke the skill with 'necessary input parameters' but does not define a constrained trigger scope or safe usage boundaries. That vagueness can lead to arbitrary or opportunistic use, especially when the rest of the document contains conflicting generic automation language.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The markdown advertises file writing, API integration, and command execution but does not prominently warn users about the security implications. In a skill that appears creative and low-risk on its face, undocumented operational side effects can cause users or agents to underestimate the sensitivity of the granted capabilities.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.