Back to skill

Security audit

监控器

Security checks for vulnerabilities and agentic risk

Overview

This monitoring skill is not overtly malicious, but it asks for broad local command execution and vague API or credential use without concrete boundaries.

Install only if you are comfortable with a monitoring assistant that may read local data and run diagnostic commands. Require the agent to show the exact command, API target, credential use, and any file change before acting, and keep it to read-only monitoring unless you explicitly approve side effects.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is overly broad, covering many operations and contexts without precise boundaries. Broad triggers increase the chance that an agent selects this skill for unrelated tasks, exposing powerful tools like exec in situations where the user did not intend elevated operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

System command execution is a powerful primitive that materially increases the risk profile of the skill. In the context of an ambiguously triggered monitoring skill, command execution can be used to run arbitrary local actions, inspect sensitive files, or modify the host system under the guise of diagnostics or monitoring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description states '支持中文交互,无需复杂配置即开即用', which presents Chinese interaction as a default capability without clarifying whether other languages are supported by user choice. In a general-purpose skill, prescribing a specific language without explicit opt-in can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The core capability statement uses broad phrasing such as creating monitors for anything, which functions like a trigger for overly expansive use. In combination with privileged tools, this can route many unrelated requests into a skill that can perform sensitive local and external actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document mentions that only allowlisted commands should be executed, but elsewhere it describes general command execution without consistently enforcing or documenting that restriction. This inconsistency is dangerous because agents and users may rely on the broader wording, leading to execution of unsafe commands despite a nominal security note.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a monitoring/alerting tool, but the documentation expands its scope into generic file handling, API integration, and command execution. This creates a capability mismatch that can cause an agent or user to invoke a far more privileged skill than expected, increasing the risk of unintended code execution, data access, or lateral misuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Advertising file writing in a monitoring skill is risky because it extends the skill from observation into modification of the local environment. If an agent relies on this skill under the assumption it is read-oriented monitoring, it could overwrite files, alter configs, or drop artifacts without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill mentions file writing, API calls, and command execution without prominent user-facing warnings about their consequences. Hidden or underemphasized side effects are dangerous because users may invoke the skill for benign monitoring and unintentionally authorize system changes, outbound communications, or local command execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes standard external API calling and credential-based setup beyond a narrowly defined monitoring role. This broadens the trust boundary to external systems and secrets handling, which can enable data exfiltration, unauthorized outbound actions, or misuse of stored credentials if the skill is activated too broadly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.