Back to skill

Security audit

管理和控制

Security checks for vulnerabilities and agentic risk

Overview

This skill is a macOS system-control helper, but it asks for broad command/file authority and describes sensitive actions without clear user confirmation boundaries.

Review before installing. Use this only in a constrained environment where the agent must ask before screenshots, clipboard reads/writes, process termination, network configuration, Finder file changes, or power actions. The artifact does not show malware or persistence, but its broad authority and unclear boundaries make careful user control important.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is overly broad and frames the skill as generally useful for efficiency, automation, batch processing, and workflow optimization, despite the skill exposing system-control and command-execution capabilities. In an agent ecosystem, this can cause the skill to be selected for ordinary productivity requests and then perform sensitive host actions such as process management, screenshots, clipboard access, or network/power changes without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises broad macOS control capabilities, including process management, screenshots, clipboard, Finder, network, and power operations, but does not place prominent warnings or approval requirements near the top-level description. In this context, the absence of clear caution materially increases the chance of destructive or privacy-invasive actions being executed through normal agent use, especially because the skill also declares exec/write capability.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described throughout the file as a macOS system-control utility that returns system status or control results, but the '结果格式' section shows a code-review style grading schema with fields like 'overall_grade', '代码风格', and '安全合规'. This is not merely incomplete documentation; it actively describes a different kind of result than the skill's claimed operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill repeatedly states it manages macOS system functions and even says it is not suitable for non-macOS devices, but the runtime requirements list 'Windows / macOS / Linux' as supported operating systems. This is a direct contradiction in the documentation about where the skill can actually be used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.