Back to skill

Security audit

智能体

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it asks for broad read, write, command execution, and API-related authority for a very loosely scoped research and automation purpose.

Install only if you are comfortable with a broadly scoped automation skill that can read files, write files, and execute commands. Use it in a constrained workspace, avoid exposing sensitive directories or API keys, and review any proposed command, file write, or external API action before allowing it.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill is presented as a research/document-processing agent, but it explicitly includes the exec tool and later advertises command execution as a feature. That creates a capability-to-purpose mismatch: users may invoke the skill for low-risk content tasks without realizing it can execute system commands, increasing the chance of unsafe delegation or abuse.

Intent-Code Divergence

Low
Confidence
67% confidence
Finding
The statement that the skill is 'not suitable' for encrypted-file cracking may appear safety-conscious, but in context it is paired with broad file-processing and command-execution capabilities. That combination can create a misleading trust signal, causing users to underestimate the operational power of the skill and use it in riskier contexts than intended.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The invocation guidance is so broad that the skill could be selected for many unrelated tasks, including ones involving files, APIs, SEO, and automation. Overbroad routing increases the chance that a high-capability skill with read/write/exec access is invoked in inappropriate contexts, which expands attack surface and misuse potential.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation advertises file writing, API integration, and command execution as normal features without prominent user-facing risk warnings or execution boundaries. In a skill environment, those capabilities can materially affect the host system or external services, so under-disclosure increases the risk of unsafe use and privilege abuse.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.