Back to skill

Security audit

规避

Security checks for vulnerabilities and agentic risk

Overview

This Vue helper is not clearly malicious, but it asks for broad read/write/command authority and describes API, webhook, and system-connection uses that do not fit its stated Vue mistake-avoidance purpose.

Install only if you are comfortable with a Vue skill that may be invoked for broader automation tasks and has read, write, and command execution authority. Treat it as under-scoped: review any proposed command or file change before allowing it, and do not provide API keys or sensitive project data unless the publisher supplies clearer operational boundaries.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill is presented as a Vue mistake-avoidance helper, but its description and declared tools expand into API integration, webhook/system connection, and command execution. This capability mismatch increases the chance that an agent will grant or invoke powerful operations under an innocuous skill name, creating a misleading trust boundary and enabling unintended file/system/network actions.

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The documentation claims the skill can automatically detect and fix Vue code issues, but no concrete implementation, bounded workflow, or verification steps are provided. This can mislead users and agents into trusting broad autonomous code modification behavior without understanding what will actually run, increasing the risk of unsafe or over-privileged execution.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation text is overly broad, saying the skill should be used for API integration, interface docking, webhook configuration, and system connections despite the skill being branded for Vue mistakes. Such broad routing language can cause the agent to select this skill in unrelated high-risk contexts, exposing powerful tools like exec/write/read when they are not contextually appropriate.

Vague Triggers

Low
Confidence
77% confidence
Finding
The manifest does not provide a specific trigger phrase list, bounded activation criteria, or exclusion guidance, which makes accidental or inappropriate invocation more likely. In a skill with read/write/exec capabilities, weak routing boundaries increase the chance of misuse even if the underlying content is not overtly malicious.

Static analysis

No suspicious patterns detected.