Back to skill

Security audit

审计

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a knowledge-base audit helper, but it overclaims security capabilities and declares broad write/command/API abilities without clear limits.

Review this skill carefully before installing. It is probably intended as a Markdown knowledge-base health checker, but do not rely on it for real security, compliance, or vulnerability assessment. Use it only on project directories you are comfortable exposing to an agent, and require explicit approval before any file writes, shell commands, or external API calls.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The skill simultaneously presents itself as pure Markdown/natural-language driven and advertises execute-capable behavior, creating a misleading trust boundary. Users may assume the skill is passive documentation while it can actually trigger command execution, increasing the chance of unsafe invocation and unintended system impact.

Vague Triggers

High
Confidence
95% confidence
Finding
The description markets the skill for broad security uses such as compliance auditing, vulnerability scanning, and encryption protection, far beyond the documented core function of checking links and metadata in a knowledge base. This overclaim can cause operators to rely on the skill for sensitive security decisions it is not designed to make, leading to false assurance and missed real vulnerabilities.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises file writing, external API integration, and command execution capabilities without a prominent warning or operational guardrails. In the context of an agent skill, this is dangerous because users may invoke it expecting a harmless documentation audit, while the capability set could modify files, run shell commands, or transmit data externally.

Static analysis

No suspicious patterns detected.