Back to skill

Security audit

效率倍增器

Security checks for vulnerabilities and agentic risk

Overview

This productivity skill is mostly coherent, but it requests unnecessary command-line authority and can modify local planning files under broad activation language.

Review this skill before installing because it should not need shell access for Markdown productivity planning. Install only if your host can deny or constrain exec, and confirm before letting it create, rewrite, delete, or reorganize files under ~/productivity/.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:22
Finding

Unnecessary Shell Execution Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22–24
Vulnerability Type: Excessive tool permissions
Risk Level: Medium

Evidence

yaml
tools:
- read
- exec

The declared capability conflicts with the Skill's own statements at lines 437–439:

markdown
### 可用性分类
- **分类**:MD(纯 Markdown 指令,无需 exec)
- **说明**:基于 Markdown 的 AI Skill,完全通过自然语言指令驱动 Agent 执行效率管理任务。所有记忆与计划通过文件读写管理,无需命令行执行能力。

The latter passage states that this is a pure Markdown Skill and that command-line execution is unnecessary.

Technical Analysis

The Skill requests the general-purpose exec tool despite documenting a workflow that only needs local Markdown file operations. Shell execution can provide substantially broader access than the productivity-management functionality requires, including access to host files, processes, environment variables, and executable programs within the Agent runtime's operating-system permissions.

Merely declaring exec does not prove that the Skill currently executes malicious commands. However, retaining an unnecessary high-impact capability violates least privilege and enlarges the consequences of malicious, misleading, or otherwise untrusted instructions processed while the Skill is active.

Attack Path

  1. The Agent loads the Skill and makes its declared exec capability available.
  2. The Agent processes attacker-controlled or misleading content during a productivity task, such as a task description copied from an untrusted source.
  3. That content induces the Agent to invoke a shell command under the pretext of organizing or processing the user's files.
  4. Because exec is unnecessarily available, the command runs with the permissions of the Agent process.
  5. Depending on runtime sandboxing and operating-system permissions, the command could inspect unrelated files, access environment data, alter local content, or launch additional processes.

This is a capabi ...[truncated 873 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the declared tools:

    yaml
    tools:
    - read
    
  2. If the Skill must create and update productivity records, declare a dedicated file-write capability rather than general shell execution.

  3. Restrict file operations to a canonicalized ~/productivity/ directory and reject path traversal, symbolic-link escapes, and writes outside that boundary.

  4. Require explicit user confirmation before creating the initial directory structure, overwriting files, deleting tasks, or moving records.

  5. Keep preference persistence opt-in, consistent with the approval requirement documented at lines 302–303.

  6. Add automated metadata validation that rejects unnecessary high-risk capabilities when the Skill documentation states that they are not required.

  7. If exec must be retained for an undocumented use case, document that use case, allowlist exact commands and arguments, run them in a sandbox, and require confirmation before execution.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill metadata and content are presented entirely in Chinese, with no indication that the user can choose another language or that the locale restriction is intentional and documented as region-specific. Under the language/locale policy, a skill should not implicitly force a specific language without offering choice or documenting the constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are broad everyday terms like '效率', '计划', and 'productivity', which can cause the skill to activate in ordinary conversations where the user did not intend file-based planning behavior. In an agent environment with file access or memory-writing behavior, overbroad activation increases the chance of unintended reads, writes, or workflow takeover.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Requesting exec for a local productivity-planning skill violates the principle of least privilege because its stated purpose only requires reading and writing planning files. Unnecessary command execution capability can be abused to run arbitrary local commands, alter unrelated files, or chain with other agent behaviors if the skill is ever invoked in an unsafe context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The privacy section says only explicitly approved ~/productivity/ files are stored locally, but the rest of the skill describes creating, rewriting, and expanding multiple files and directories as part of normal operation. That inconsistency can mislead users about when persistence happens and what data will be written, undermining informed consent and potentially causing sensitive work data to be stored unexpectedly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims it is a pure Markdown skill that does not need exec, yet the manifest requests the exec tool. This mismatch weakens least-privilege guarantees and can cause a host agent to grant command-execution capability that is unnecessary for the documented workflow, increasing the blast radius if the skill is modified, misused, or prompt-injected later.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The “何时使用” section describes broad situations such as wanting a real productivity system, needing review, or converting goals to plans, but it does not clearly define activation boundaries or exclusions. Because these situations are expansive and lack non-applicable examples, the invocation criteria remain ambiguous for a markdown skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.