Back to skill

Security audit

爆款拆解师

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a marketing-content analysis guide, but it asks for broad command and file permissions that are not clearly needed.

Review this skill carefully before installing. It appears to be a text-analysis prompt, not malware, but grant it only the minimum permissions needed; avoid enabling command execution, filesystem write access, or broad file search unless you specifically intend to use those unrelated advanced capabilities.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill claims to be 'pure LLM-driven' with no extra API dependencies while also describing command execution, file handling, and broader operational capabilities elsewhere. This inconsistency can mislead users and host agents about the actual trust boundary, causing the skill to receive more privileges than its stated purpose warrants.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill requests read, write, exec, glob, and grep even though its stated function is content decomposition and scoring. Overbroad capabilities increase the attack surface: if the skill is invoked on attacker-controlled input or later extended with tool-using instructions, it could search local files, modify data, or execute commands unrelated to the user’s task.

Intent-Code Divergence

High
Confidence
90% confidence
Finding
The file’s documented purpose shifts from viral-content analysis to code static analysis, dependency vulnerability detection, batch code review, and CI/CD integration. This scope creep is dangerous because it obscures the real operational profile of the skill and may normalize granting developer-grade privileges to a marketing-analysis tool.

Static analysis

No suspicious patterns detected.