Back to skill

Security audit

网页爬取工具

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a Discord/web scraping helper, but its scope is inconsistent and it advertises sensitive DM archiving plus anti-bot evasion features without adequate safeguards.

Review carefully before installing. Only use this skill for accounts, servers, channels, and messages you are authorized to access, and avoid any anti-bot, cookie-rotation, or IP-rotation workflows unless you have a clear lawful basis and platform permission. The publisher should narrow the scope and replace the mismatched examples before users rely on it.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The documentation narrows scope to Discord-only archiving but elsewhere advertises generic web-scraping capabilities including anti-bot evasion and IP/cookie rotation. This inconsistency can mislead users and reviewers about the true operational scope, increasing the chance the skill is used for broader scraping or policy-evasion workflows than expected.

Intent-Code Divergence

Low
Confidence
81% confidence
Finding
The documented output schema is unrelated to the stated Discord archiving or crawling purpose and instead resembles a grading/report template. Mismatched interface documentation is dangerous because it obscures what the tool really does, impedes safe review, and may hide unexpected data processing or execution behavior behind misleading examples.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manifest description is internally inconsistent, mixing Discord archiving, SEO optimization, and generic web crawling. In an agent skill, unclear purpose and trigger conditions increase the risk of accidental invocation in unrelated contexts and make it harder to assess what data sources, permissions, and behaviors the skill may exercise.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Broad, inconsistent invocation language can cause the agent or user to apply the skill in contexts far beyond its intended function. Because the skill also exposes exec/read/grep/glob capabilities, ambiguous triggering materially raises the risk of unsafe or privacy-invasive use on unrelated tasks.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill advertises DM archiving/searching without prominent privacy, consent, retention, or authorization guidance. Handling direct messages is inherently sensitive, and absent warnings or safeguards can lead to collection, storage, or querying of private communications without appropriate legal basis or user awareness.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Advertising anti-bot evasion, cookie-pool management, and IP rotation without strong upfront warnings normalizes policy-evasion behavior and can facilitate unauthorized scraping. In this skill context, those features are especially dangerous because they suggest deliberate bypass of platform controls, raising legal, account-security, and abuse risks.

Static analysis

No suspicious patterns detected.