Back to skill

Security audit

规避

Security checks across malware telemetry and agentic risk

Overview

This Vue helper is not clearly bounded: it asks for broad read, write, command, API, and integration abilities that are wider than its stated Vue troubleshooting purpose.

Review this skill carefully before installing. It may be reasonable only if you want a broad automation helper with read/write/command abilities, not just Vue advice. Use it in a limited workspace and avoid providing API keys or sensitive project data unless the publisher clarifies exact command, file, and network boundaries.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

High
Confidence
92% confidence
Finding
The skill is presented as a narrow Vue troubleshooting/helper skill, but its description also advertises generic API integration, webhook/system connection, and automation behavior. This scope mismatch can cause an agent to invoke a much more capable skill than the user expects, increasing the chance of unintended file, network, or command actions under a misleading label.

Intent-Code Divergence

Medium
Confidence
76% confidence
Finding
The document mixes a claim of narrow Vue-focused behavior with language about flexible automated configuration and parameterized operation. That inconsistency makes the skill's effective behavior ambiguous, which can lead orchestrators or users to trust it for benign code guidance while it is eligible for broader operational tasks.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The FAQ claims the skill can automatically detect and fix Vue errors, but the declared tools and surrounding documentation mainly expose generic read/write/exec and API-style capabilities without defining a bounded Vue analysis workflow. This gap can hide what actions will actually be taken and may permit overly broad automated modification or execution under the guise of code fixing.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The feature list and rollout steps openly describe file processing, external API calls, and system command execution, which are far broader than a Vue mistake-avoidance assistant. In the context of a skill with exec/read/write tools, this mismatch is dangerous because it can be selected for routine development help yet still perform powerful side-effecting actions.

Vague Triggers

High
Confidence
90% confidence
Finding
The activation language is so broad that many unrelated tasks involving APIs, integrations, webhooks, or system connections could match, even though the skill is branded as Vue-focused. Over-broad matching increases the probability that an agent will route sensitive or operational tasks to a skill with unnecessary exec/read/write powers.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.