Back to skill

Security audit

轻量工作流

Security checks for vulnerabilities and agentic risk

Overview

This is a simple no-code workflow guide, but it asks for command-execution permission that its own Markdown-only purpose does not need.

Review this before installing. The workflow advice itself is ordinary, but the skill should not need shell-command access for Markdown guidance. Prefer a version with exec removed, and be careful not to send full customer, payment, receipt, or report data into Slack or email unless recipients, retention, and masking are appropriate.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:36
Finding

Unnecessary Command-Execution Permission Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 36-38
Vulnerability Type: Excessive tool permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec

The declared permissions conflict with the Skill's own description at lines 206-208:

markdown
### 可用性分类
- **分类**:MD(纯Markdown指令)
- **说明**:极简入门skill,通过自然语言指令驱动Agent辅助用户在无代码平台搭建最小工作流

Technical Analysis

The Skill declares access to the exec tool even though its documented functionality consists entirely of static Markdown guidance for designing no-code workflows. No instruction in the reviewed file requires local command execution. Local file-reading access also appears unnecessary for the stated functionality.

Granting command-execution capability beyond legitimate operational requirements violates the principle of least privilege. Although the reviewed Skill contains no malicious command, script, or direct instruction to invoke exec, the excessive capability increases the consequences of future modification, compromised surrounding context, or instruction injection. An attacker-controlled instruction interpreted while the Skill is active could attempt to use the already-authorized execution tool.

Attack Path

  1. An agent loads the Skill and grants the tools declared in its front matter, including exec.
  2. The agent subsequently processes attacker-controlled or compromised instructions in the same operational context.
  3. Those instructions induce the agent to invoke exec, despite command execution not being required by the Skill's intended function.
  4. Commands execute with the operating-system privileges and environmental access available to the hosting agent.
  5. The resulting impact depends on sandboxing, approval controls, filesystem permissions, network restrictions, and the privileges of the agent process.

This is a conditional exposure rather than evidence that the current Skill itself ...[truncated 685 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the tools declaration because no documented feature requires command execution.
  2. Remove read as well unless the Skill is intentionally extended with a narrowly defined local-file operation.
  3. Declare no tools for this Markdown-only educational Skill.
  4. If command execution becomes necessary in a future release, document the exact commands and operational purpose, use an explicit allowlist, require user confirmation, and run commands in a restricted sandbox.
  5. Apply filesystem, network, environment-variable, and process-level restrictions to any execution tool exposed by the hosting agent.
  6. Add a release review that compares declared tools against actual functionality and rejects permissions that lack a concrete use case.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is a pure Markdown beginner guide for no-code automation, yet its manifest exposes the exec tool, which enables command execution beyond the documented need. This unnecessarily expands the agent's capability surface and could let downstream prompts or users invoke shell commands in contexts where only read-only guidance was intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The templates instruct users to send form submissions, payment events, receipts, stakeholder reports, and API-derived data through email or Slack without any privacy, minimization, or secrets-handling guidance. In practice, this can cause personal, financial, or sensitive business data to be copied into third-party channels or logs, increasing the risk of data leakage and compliance violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.