Back to skill

Security audit

Namecheap DNS工具

Security checks for vulnerabilities and agentic risk

Overview

This Namecheap DNS skill is not clearly malicious, but it needs review because it requests broad read/write/exec authority for destructive DNS changes while parts of its metadata and documentation describe unrelated capabilities.

Install only if you specifically need Namecheap DNS administration and are prepared to supervise every DNS change. Use dry-run and verify before applying changes, avoid --force unless you have manually checked the records that may be deleted, and do not use this skill for project management, security auditing, or general automation tasks until the metadata and execution scope are narrowed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description contains an overly broad, unrelated usage trigger for project management and team collaboration. This can cause unintended skill selection in non-DNS contexts, exposing read/write/exec functionality and potentially infrastructure credentials to workflows that never needed DNS access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims capabilities such as deep vulnerability scanning, CVE correlation, compliance auditing, asset risk scoring, and threat-intelligence subscriptions that are unrelated to Namecheap DNS management. Inflated or misleading capabilities can induce excessive trust, broaden invocation in high-risk security workflows, and cause users or agents to rely on nonexistent controls before making destructive DNS changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description mixes unrelated project-management and team-collaboration use cases into a DNS-management skill. This can cause the agent to invoke or trust the skill in contexts far outside DNS administration, increasing the chance that privileged read/exec/write capabilities are applied to the wrong task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description explicitly states '支持中文交互' as a behavior, and the document is primarily written to enforce Chinese-language interaction without mentioning that the user can choose another language. This is a natural-language locale policy issue because it imposes a language preference without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The metadata mixes broad automation/tooling/security tags with a narrow DNS-administration purpose, making the skill discoverable for unrelated tasks. Overbroad tagging increases accidental invocation and misplaced trust in contexts where the skill's permissions and destructive semantics are inappropriate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares generic exec capability in addition to read/write, even though its stated purpose is DNS management. Unnecessarily broad command-execution authority increases the blast radius if the skill is invoked in the wrong context or if downstream prompts steer it into arbitrary shell actions, especially because DNS administration often involves sensitive credentials and production domains.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The line describes the skill's core functionality as providing Chinese interaction, but does not indicate that language can be selected by the user. This can conflict with language/locale policy expectations requiring user choice rather than a forced default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented result format describes scoring, audit, and improvement-report outputs unrelated to DNS changes. Misaligned output contracts can cause calling agents or users to misunderstand what actions occurred, mishandle results, or trust fabricated completion states for sensitive infrastructure operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The dependency section says the skill is 'MD(纯Markdown指令,通过自然语言驱动Agent完成操作)', implying a pure Markdown skill, while earlier sections explicitly classify it as 'MD+execute()' and declare read/exec/write tools. That is an active documentation contradiction about whether the skill performs executable operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.