Back to skill

Security audit

分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is presented as a GitHub PR mergeability checker, but it requests broad file and command powers and gives vague execution instructions, so it should be reviewed before use.

Install only if you are comfortable granting this skill read, write, and command-execution authority in a tightly sandboxed workspace. Use a least-privilege GitHub token, avoid exposing broad environment credentials, and require explicit approval before any command execution or file writes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:22
Finding

Excessive Filesystem and Command-Execution Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and top-level description present the skill as a narrow GitHub PR mergeability analyzer, but the content expands it into generic data analysis, visualization, file processing, API use, and command execution. That scope drift is dangerous because it can cause an agent or user to grant broader trust and capabilities than are justified by the stated purpose, increasing the chance of unintended file access, command execution, or misuse under a misleading label.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invocation and description are overly broad, inconsistent, and partially unrelated to PR mergeability, including generic analytics and reporting language. This weakens user consent and agent policy alignment because the skill can be invoked under a narrow expectation while actually encouraging much wider behaviors and tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description explicitly states '支持中文交互,无需复杂配置即开即用', and the document is predominantly written as Chinese-first guidance without offering a language choice. Under the language/locale policy, this is a concern unless the skill clearly offers opt-in or justifies a locale restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation inconsistently describes the skill as both a pure Markdown instruction skill and an executable skill. This ambiguity is dangerous because reviewers and agent runtimes may misunderstand what privileges the skill expects, leading to accidental enablement of execution features or weaker scrutiny than an executable skill warrants.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Advertising generic file read/write handling in a skill that is supposed to assess GitHub PR mergeability unnecessarily broadens the operational scope. In an agent environment, this can normalize unrelated filesystem access and make it easier to exfiltrate, overwrite, or process local files outside the user’s expected task boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly advertises system command execution without tightly binding that capability to a minimal PR-analysis workflow. Even when described as sandboxed, normalizing arbitrary command execution in a loosely scoped skill raises the risk of command abuse, environmental probing, token exposure, or execution of attacker-influenced commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.