Back to skill

Security audit

claude组合包

Security checks across malware telemetry and agentic risk

Overview

This bundle is not clearly malicious, but it requests broad agent powers such as file edits, shell execution, and API credentials without enough scoping for a simple bundle listing.

Review this before installing. Treat it as a high-authority agent bundle, not just a catalog item: only use it in workspaces where file modification and shell commands are acceptable, avoid giving broad API keys, and confirm each bundled skill’s behavior before allowing access to sensitive projects or credentials.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The file presents itself as a marketing/bundle manifest, but the body documents operational capabilities including file writes, command execution, and API usage. This is dangerous because users may enable or trust the bundle under a low-risk packaging assumption while it effectively grants higher-risk execution and modification behaviors.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The section emphasizes benign data processing and workflow automation, but later functionality includes shell execution and file modification that are materially more sensitive. This mismatch can mislead operators and reviewers, increasing the chance of over-privileged deployment or unsafe invocation.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Documenting shell command execution in a bundle whose stated purpose is marketing/integration is unjustified and expands the attack surface significantly. If accepted at face value, users may permit arbitrary command execution in contexts where only orchestration or cataloging functionality was expected.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The bundle-level documentation requests or supports API credentials and external service access without clearly tying that need to the bundle's advertised purpose. This can cause users to supply secrets to a package they perceive as a simple bundle, creating unnecessary exposure of credentials and outbound data flows.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises file writing, API access, and command execution without a prominent user-facing warning about their security impact. In a bundle context, these capabilities can be abused for arbitrary file changes, secret exposure, or system command execution if users are not clearly informed and controls are not explicit.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.