Back to skill

Security audit

社区垃圾过滤

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a community spam-feed filter, but it asks for broad agent tools and under-scoped credential-file access that users should review before installing.

Install only if you are comfortable letting the agent run Node.js commands and inspect local API-key configuration for this filtering workflow. Prefer using a narrowly scoped read-only API token in an environment variable, avoid callback URLs unless you trust the endpoint, and review any blocklist or filtering-rule edits before applying them.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:131
Finding

Overbroad and Inconsistent Access to Credential-Bearing Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 131–144
Vulnerability Type: Excessive access to credential-bearing files
Risk Level: Medium

Vulnerable Instructions

The following is an English translation of the complete relevant instructions:

text
- Credential read: `$HOME/.config/platform/config.json`
text
1. Confirm that the configuration file `$HOME/.json` exists and that the API key is valid.

Technical Analysis

The Skill instructs the Agent to access files in the user's home directory that may contain API credentials. It does not define the exact configuration fields that may be read, prohibit returning file contents, require secret redaction, or provide an implementation demonstrating that unrestricted credential-file access is necessary.

The two instructions also identify inconsistent paths: $HOME/.config/platform/config.json and the unusually broad $HOME/.json. This inconsistency can cause an Agent to inspect an unintended file containing unrelated credentials or private configuration.

Although the filtering workflow may legitimately require an API token, credential handling should be restricted to a dedicated environment variable or a narrowly scoped configuration field. The current instructions unnecessarily expose secret-bearing files to the Agent and its tool context.

No evidence was found that the Skill deliberately transmits credentials to an external service. The risk is unauthorized exposure through Agent context, command output, execution logs, or downstream generated content rather than confirmed exfiltration.

Attack Path

  1. A user activates the Skill to scan or filter a community feed.
  2. The Agent follows the setup instructions and accesses one of the specified home-directory configuration files.
  3. Because the allowed fields and access method are not constrained, the Agent may read the complete file while attempting to validate the API key.

...[truncated 789 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove instructions that encourage reading complete credential-bearing files.
  2. Use a dedicated environment variable such as PLATFORM_API_KEY and access only that variable.
  3. If a configuration file is required, standardize on one application-specific path and document the exact permitted JSON field.
  4. Explicitly prohibit printing, logging, returning, or persisting API keys and complete configuration-file contents.
  5. Validate only whether the required field is present; do not display its value.
  6. Redact tokens in errors and diagnostic output, retaining only a short non-sensitive identifier if necessary.
  7. Require a narrowly scoped, read-only API token with minimal permissions and support straightforward token rotation.
  8. Remove the conflicting $HOME/.json reference and use a clearly named application-specific file with restrictive filesystem permissions.
  9. Add an executable implementation that performs bounded parsing and secret-safe validation so credential handling can be independently audited.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description includes very broad 'use when' language covering generic efficiency, automation, batch processing, and workflow optimization. In agent ecosystems, overly broad invocation criteria can cause the skill to trigger in unrelated contexts, potentially granting unnecessary access to exec/read/write capabilities and increasing the chance of unsafe use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented callback_url parameter enables sending processing results to an external endpoint, but the skill provides no warning, trust boundary, validation rules, or restrictions on what data may be transmitted. This creates SSRF and data exfiltration risk, especially in an agent context where user-supplied URLs may point to attacker-controlled or internal network targets.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The architecture section at L102-L106 says the skill is a client-side read-only filter that does not post, comment, or modify anything. However, other sections describe '识别并移除' spam posts (L39), '自动化黑名单管理' (L241), and '手动移除垃圾帖 -> 自动化耗时 1秒/帖' (L221), which suggests deletion or active moderation rather than local filtering only.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Lines L103-L106 explicitly state the filter only reads APIs, does not modify content, and does not send data to third-party services. Elsewhere, the same file requires an API key (L65-L68, L73-L77), references API connectivity failures (L249, L274-L276), and discusses network communication security (L265), which contradicts the no-third-party-data/no-network implication of the architecture description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The description explicitly says the skill supports Chinese interaction, but it does not indicate whether other languages are supported or give users a choice of language. Because policy violations include forcing a specific language or locale without opt-in, this wording can be read as a language constraint that is not clearly optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.