Back to skill

Security audit

设计

Security checks for vulnerabilities and agentic risk

Overview

This MongoDB skill is Markdown-only and not malicious, but it asks for broad read/write/command authority while its documentation is inconsistent and under-scoped.

Review before installing. This does not show exfiltration or destructive code, but it gives an agent broad read/write/command capabilities under a MongoDB label with unclear boundaries. Only use it in a constrained workspace and approve file writes, API calls, and shell commands case by case.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a MongoDB schema/query/configuration assistant, but its documented capabilities extend to generic file processing, API integration, and command execution. This scope expansion increases the attack surface and can mislead users into granting trust and permissions not justified by the stated purpose, enabling unintended high-impact actions under a narrow database-oriented label.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises file writing, API calls, and command execution without prominent user-facing warnings about potential system modification, data loss, credential exposure, or network egress. Users may invoke the skill expecting safe advisory behavior, while the documented capabilities permit actions that can change local state or interact with external services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Documenting system command execution as a core capability for a MongoDB-focused skill is dangerous because command execution can be used to access files, modify the host, exfiltrate data, or run arbitrary programs far beyond database assistance. In this context, the capability is insufficiently justified and lacks any meaningful restriction or sandbox policy, making misuse materially more dangerous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The display name and substantial portions of the skill description are presented in Chinese, while the file does not state that users may choose their preferred language or locale. Under the policy, language constraints or forced locale presentation should either be optional for the user or clearly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is introduced throughout the manifest as a MongoDB assistant, but the '专业版增值服务' table lists capabilities such as high-resolution lossless output, style presets, model fine-tuning, and commercial copyright authorization. These are characteristic of media-generation tooling, not MongoDB schema/query/configuration work, indicating the documentation contradicts the actual stated intent of the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.