Back to skill

Security audit

爬虫网页

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a web-scraping helper, but its documentation and requested powers are much broader than that purpose explains.

Review this carefully before installing. Use it only for controlled webpage scraping, and avoid granting broad read, write, or command execution access unless the publisher narrows the documentation and explains exactly what commands, files, URLs, credentials, and outputs are in scope.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The skill is declared as a simple web-scraping tool, but the documentation broadens its scope to generic AI/LLM usage, data analysis, API integration, file handling, and command execution. This kind of capability inflation can mislead an agent into granting the skill broader authority or invoking it in contexts far beyond scraping, increasing the chance of unsafe execution and privilege misuse.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
Advertising unrelated paid features such as static analysis, dependency vulnerability detection, CI/CD integration, and refactoring advice inside a web-scraping skill creates deceptive scope expansion. In an agent ecosystem, this can cause over-selection of the skill for sensitive software tasks and expose code, secrets, or workflows to a tool that was not intended or reviewed for those purposes.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Overly broad invocation guidance makes it unclear when the skill should activate and encourages use in unrelated AI, analytics, and workflow scenarios. In agent-driven systems, ambiguous triggers can route sensitive or high-impact tasks to a skill with exec/read/write capabilities, expanding attack surface and enabling unintended actions.

Static analysis

No suspicious patterns detected.