Back to skill

Security audit

文档扫描增强

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to perform document image enhancement, but it can send sensitive document images to an unspecified external service and its activation scope is broader than its stated purpose.

Review this skill carefully before installing. Use it only for images you intend to send to the scan service, avoid private IDs, contracts, receipts, or confidential documents unless you trust the provider, and narrow the activation text to explicit document/image enhancement requests.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises broad activation conditions such as code generation, debugging, testing, and deployment, which are unrelated to the actual document-scanning purpose. Overbroad triggers can cause the agent to invoke this skill in inappropriate contexts, sending unintended files or image data to an external service and creating data handling and privacy risk.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The fallback rule for `scan-document` is vague and effectively authorizes execution whenever a user expresses a generic optimization intent. In an agent setting, ambiguous fallback behavior increases the chance of unintended external processing of user-provided content, especially when the skill also supports local paths, URLs, and base64 inputs.

Static analysis

No suspicious patterns detected.