Back to skill

Security audit

Namecheap DNS工具

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a Namecheap DNS management guide, but its routing and documentation mix in unrelated project-management and assessment claims around high-impact DNS-changing workflows.

Review before installing. Use this only for explicit Namecheap DNS work, and do not rely on the project-management or assessment claims. Because DNS updates can replace all records for a domain, require dry-run or diff review, verify ghost records, keep backups, and avoid --force unless the DNS deletion impact is understood.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The manifest description mixes DNS-management behavior with unrelated project-management and team-collaboration use cases, creating a capability mismatch. In an agent ecosystem, this can cause the skill to be selected in inappropriate contexts, leading the agent to expose DNS tooling and API-backed mutation paths when the user asked for unrelated workflow help.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The declared result schema shows grading, scoring, and improvement advice unrelated to DNS operations, which misrepresents what the skill returns. This can mislead an orchestrating agent into treating destructive infrastructure actions as a harmless assessment workflow, weakening user awareness and validation around DNS changes.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
Advertising unrelated capabilities like CVE correlation, compliance auditing, and asset risk scoring broadens the perceived trust boundary of the skill beyond DNS management. This increases the chance that an agent or user grants it authority, sensitive data, or execution opportunities under false assumptions about its function.

Vague Triggers

High
Confidence
99% confidence
Finding
An overly broad 'Use when' trigger can cause the agent to invoke this DNS skill during unrelated project-management interactions. Because the skill exposes read/exec/write tooling and documents destructive DNS update flows, incorrect routing could escalate a benign conversation into infrastructure-affecting actions or unnecessary credential handling.

Static analysis

No suspicious patterns detected.