Back to skill

Security audit

Logo品牌设计工具

Security checks for vulnerabilities and agentic risk

Overview

This logo skill is not clearly malicious, but it asks for file and command powers while also describing unrelated operations work, code review, API use, and command execution.

Install only if you are comfortable with a poorly scoped skill that may be routed beyond logo design. A safer version should remove exec, limit or remove file read/write access, and rewrite the documentation so it is strictly about logo prompt generation, validation, and export guidance.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:20
Finding

Overprivileged Tool Declaration for a Logo-Generation Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-23
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

Technical Analysis

The skill declares unrestricted reading, writing, and command-execution tools even though its stated primary purpose is to develop logo prompts and guide image generation. In particular, the exec capability is not required by the documented prompt-generation workflow.

Granting these capabilities violates the principle of least privilege. If the hosting agent authorizes tools according to this manifest, the skill receives access to operating-system commands and local files beyond the minimum access necessary for its stated purpose.

The document contains no executable scripts, malicious commands, remote payload retrieval, persistence behavior, or explicit data-exfiltration instructions. Therefore, this finding concerns the exposed privilege boundary rather than evidence that the skill currently exercises those permissions maliciously.

Attack Path

  1. A user loads or invokes the logo-generation skill.
  2. The hosting platform grants the declared read, write, and exec tools.
  3. Attacker-controlled or untrusted content is introduced through a logo request, copied design brief, external model response, or later modification to the skill instructions.
  4. The agent is induced to invoke one of the unnecessarily available tools.
  5. Subject to the agent sandbox and operating-system permissions, commands could be executed or local files could be inspected or modified.

This attack path is conditional: the audited file does not itself contain instructions that perform these actions. Exploitation requires an additional prompt-injection source, malicious modification, or unsafe agent behavior.

Impact Assessment

Potential impact depends on the host platform's ...[truncated 697 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec because the documented logo prompt-generation workflow does not require operating-system command execution.
  2. Remove read and write unless the skill implements a specific, documented file import or export operation.
  3. If file access is required, restrict it to explicit user-selected input files and a dedicated output directory.
  4. Require interactive user approval before any file write, external API request, or command execution.
  5. Run image-generation integrations through a narrowly scoped API tool rather than a general-purpose shell.
  6. Apply filesystem, process, and network sandboxing at the host level; do not rely solely on skill instructions.
  7. Document each required capability, its allowed targets, and its expected operation so reviewers can verify that the manifest follows least privilege.
  8. Add tests that reject undeclared paths, shell metacharacters, arbitrary executable names, and attempts to access credentials or unrelated project files.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description combines a logo-generation skill with unrelated system monitoring, log analysis, deployment, and ops-management use cases. This kind of scope confusion can cause an agent to invoke the skill in contexts far beyond its stated purpose, especially since the skill also declares read/write/exec tools, increasing the chance of unnecessary privileged actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation advertises logo design but also claims code analysis, vulnerability detection, batch code review, and CI/CD integration. These unrelated high-privilege capabilities can mislead an agent into treating the skill as suitable for software-security or pipeline tasks, enabling unintended access paths or execution flows that are not justified by the core logo-design function.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is overly broad and ambiguous, mixing multiple domains and giving little guidance on when the skill should or should not be called. In an agent environment, vague routing criteria can cause the skill to be selected for inappropriate tasks, which is more dangerous here because the skill advertises privileged tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description explicitly states '支持中文交互' as part of the skill behavior, and the file predominantly presents instructions in Chinese without offering a language choice. This can violate language or locale policy when the skill appears to impose a specific language by default rather than allowing user preference.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill declares exec capability even though its stated role is logo generation. Unnecessary command execution materially increases risk because an agent may run shell commands in service of a loosely defined task, expanding the attack surface without a legitimate need tied to the skill's core purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The application scenarios are generic content-processing workflows with vague 'execution status' outputs instead of logo-specific artifacts. Ambiguous task framing broadens the situations in which an agent may invoke the skill, creating prompt-routing risk and making misuse more likely when powerful tools are available.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The later documentation expands the role into generic file handling, API integration, and sandboxed command execution, none of which are clearly necessary for a logo-design helper. In context, these claims normalize broader operational behavior and can encourage an agent to perform sensitive actions under a benign creative pretext.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The instructions tell users to 'call this skill in the AI Agent conversation' without defining concrete invocation phrases, required context, or situations where it should not activate. In markdown skill descriptions, this kind of generic invocation wording can lead to ambiguous routing and unintended use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.