Back to skill

Security audit

Yq Find Skills

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed skill-discovery helper with broad activation wording, but no executable code or hidden behavior was found.

Install this if you want an agent to help discover and recommend skills. Because it can recommend changes to mounted skills, review any mount, unmount, update, or priority-change recommendation before approving it, especially in shared team environments.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions are very broad and include generic phrases like '需要为当前任务寻找合适的技能' and 'Agent团队需要能力扩展', which can match ordinary discussion rather than an explicit request to invoke this skill. In a meta-skill that can influence skill discovery and mount/unmount workflows, unintended activation can cause unnecessary recommendations, workflow hijacking, or escalation into privileged operational paths if downstream controls are weak.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manifest description embeds multiple broad trigger phrases directly in metadata without constraints, increasing the chance that routing or discovery systems auto-select this skill during normal conversation. Because this is a meta-skill for discovering and managing other skills, over-selection is more dangerous than in a narrow informational skill: it can bias agent planning, expose skill inventory context, or initiate management-oriented flows unexpectedly.

Static analysis

No suspicious patterns detected.