Back to skill

Security audit

solo-build-free

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plan-based coding assistant that is mostly coherent, but it can automatically change files, run commands, commit code, and use unsafe rollback guidance without clear user approval.

Install only if you want an agent to carry out planned coding tasks in a repository. Before use, keep a clean git state, review the selected plan.md/spec.md, and require approval before file writes, commits, or any rollback command such as git checkout.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description explicitly says the skill should be used for '开发部署' scenarios, implying deployment-related use. Later documentation states '不适用于: ... 部署(用 /deploy)', which narrows the actual behavior away from deployment. This creates a semantic mismatch in the skill's claimed scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation scope is broad enough to match many ordinary coding, debugging, and deployment-adjacent requests, increasing the chance the skill is invoked in contexts where users do not expect repository mutation or command execution. Because the skill has read, write, and exec tools and advertises automated workflow behavior, overbroad triggering materially raises the risk of unintended destructive or sensitive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes automatically changing task state, implementing code, running tests, and committing changes without a prominent up-front warning or consent checkpoint. In a skill with write and exec privileges, silent repository modification can lead to unintended code changes, polluted git history, secret inclusion in commits, and difficult-to-reverse workflow disruption.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation says the context-loading phase '不读源码' and repeats that only specified documents are read. However, the execution loop explicitly uses code search and then reads source files such as src/auth/login.ts, which directly contradicts the earlier stated behavior rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Using git checkout as rollback guidance without a strong warning can discard uncommitted local changes and destroy user work. In the context of an automated build skill with exec access, this is especially dangerous because rollback may be triggered during error handling when users are least likely to expect irreversible loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The visible display name, summary, and operational description are written in Chinese, and the file does not state that users may choose another language. Because the skill presents its instructions in a single language without opt-in or justification as a region-specific tool, it may violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The limitations section says the skill does not support deployment, yet later feature and security sections describe external API integration and network communication as built-in capabilities. For a plan-execution engine that excludes deployment, those claims create conflicting intent signals about what the skill is supposed to do.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.