Back to skill

Security audit

网页浏览助手免费版

Security checks for vulnerabilities and agentic risk

Overview

This skill is a basic web browsing and search instruction file, with expected network-use privacy considerations but no hidden code or destructive behavior found.

Install only if you are comfortable with an agent using internet search/fetch tools for your prompts. Do not use it with confidential URLs, private logged-in pages, secrets, or sensitive business data unless you explicitly trust the destination services and any callback URL involved.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description uses very broad trigger language such as general SEO, keyword analysis, ranking improvement, and traffic optimization without clear boundaries on when the skill should or should not be invoked. In an agent environment, ambiguous routing can cause the skill to be selected for loosely related requests and lead to unnecessary web access, data transmission, or overbroad use beyond the user's intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documents fetching URLs, summarizing remote content, performing searches, and accepting an optional callback URL, but it does not clearly warn that user-provided data, URLs, or results may be transmitted to external services. This creates privacy and security risk because users may unknowingly send sensitive URLs, query terms, or extracted content to third-party sites or callback endpoints.

Static analysis

No suspicious patterns detected.