Back to skill

Security audit

产物验证门禁

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a verification helper, but it asks for command execution and file-writing authority without clear limits or privacy controls.

Review this skill carefully before installing. It may be reasonable only in a tightly sandboxed environment where command execution, file writes, network/API calls, and artifact submission to external services are explicitly approved and limited. Do not use it on sensitive source code or credentials unless those data flows are clarified.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:19
Finding

Overprivileged and Unrestricted Agent Tool Declaration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

A skill presented as an artifact verification/policy gate should normally require read-only analysis, but this one declares system command execution and file writing. Those extra privileges materially expand the attack surface: untrusted artifact content or broad user prompts could trigger state-changing actions unrelated to verification, enabling local system impact or data tampering.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance says the skill should be used broadly whenever AI model calls, agent orchestration, or LLM applications are involved. Such broad applicability encourages use outside the narrow context of artifact verification, increasing the chance that a privileged skill is invoked in inappropriate workflows where its exec/write/API capabilities create unnecessary risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises file writes, command execution, and external API usage without a clear warning that these actions may change the system or transmit user data. Users may assume a verification gate is non-invasive, so the missing disclosure undermines informed consent and can lead to unsafe invocation in sensitive environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes LLM API dependency and API-key configuration but does not clearly warn that submitted artifacts may be sent to an external model service. For a tool intended to inspect potentially sensitive AI-generated code or configurations, this creates a real privacy and confidentiality risk if users provide proprietary or secret-bearing content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The feature list advertises external API integration and command execution even though the skill is framed as a verification gate. This normalizes higher-risk behaviors for a task that users may reasonably expect to be passive, making inadvertent data exfiltration or unsafe command use more likely in practice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation claims the skill is pure Markdown/natural-language driven, while the manifest elsewhere declares read/exec/write capabilities. This inconsistency can mislead users and host agents about the skill's actual privilege level, increasing the risk of unexpected file modification or command execution under the guise of a passive verification tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.