Back to skill

Security audit

agent-copi组合包

Security checks across malware telemetry and agentic risk

Overview

This bundle is not overtly malicious, but it asks for broad command, file, API, and memory capabilities without clear limits.

Treat this as a Review item before installing. Use it only in a workspace where broad file access, editing, shell commands, and possible API credentials are acceptable, and avoid giving it sensitive customer, financial, or credential data unless you have separately verified the member skills and can constrain their access.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file is declared as a marketing bundle/plug, but it advertises direct operational capabilities such as command execution, file editing, and API-style processing as if the bundle itself performs them. This capability inflation can mislead users and downstream agents into granting or invoking powerful actions under false assumptions, increasing the chance of unsafe execution paths.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The documentation claims database access, external/API integration, file manipulation, and end-to-end automation that are not clearly supported by the bundle-focused description. In an agent ecosystem, overstated capabilities can cause operators or autonomous systems to expose sensitive data, credentials, or workflows to a package that is not appropriately scoped or reviewed for those actions.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
This marketing-oriented bundle declares high-risk tools including exec and bash without a clear functional need tied to its stated purpose. Unjustified command-execution capability is dangerous because it expands the attack surface significantly and may enable arbitrary local operations if an agent trusts the manifest and grants these permissions.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill text instructs users to configure API keys and establish external service connections even though the bundle's role is presented as packaging/integration rather than a clearly bounded network client. Encouraging credentialed connectivity without strong justification or scope boundaries raises the risk of unnecessary secret exposure and misuse of external services.

Vague Triggers

Low
Confidence
89% confidence
Finding
The bundle's use case advertises broad access to powerful capabilities such as read, write, exec, Bash, Edit, glob, and grep across multiple member skills, but it does not define any trigger boundaries, approval requirements, or exclusion conditions. In an agent context, this kind of unconstrained tool orchestration increases the chance of overbroad execution, unsafe file/system modification, or misuse of sensitive data when invoked in ambiguous user workflows.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.