Back to skill

Security audit

安全审核标准 - 自动化版

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local skill scanner, but its broad automatic activation and unreliable install-safety recommendations warrant review before installation.

Install only if you want a lightweight local heuristic scanner and will treat its results as advisory. Do not rely on its allow-install output as proof that a skill is safe, and prefer explicit invocation with a reviewed target path or manual review of any files it skips.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scan_skills.py:244
Finding

Attacker-Controlled Paths Can Bypass Security Scanning

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scan_skills.py:104
Finding

Exact-Substring Detection Is Trivially Evaded and Produces Unsafe Risk Scores

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scan_skills.py:69
Finding

Spoofable Filename Whitelist Mislabels Untrusted Files and Does Not Apply Its Intended Score Reduction

Content
View full analysis
bool: """检查文件是否为已知安全工具(白名单)""" name = os.path.basename(path).lower() for pat in SAFE_PATTERNS: if pat in name: return True return False ``` ```python if kw not in content: continue # 如果在白名单工具中,扣分减半 deduction = DEDUCTION[level] * (0.5 if is_whitelisted(path, kw) else 1.0) for i, line in enumerate(lines): if kw in line: result["详情"].append({ "级别": level, "关键词": kw, "行号": i + 1, "上下文": line.strip()[:150], "修复建议": fix_tip, "白名单": is_whitelisted(path, kw), }) break ``` ```python # 计算扣分(每个关键词只扣一次) seen_kw = set() for d in result["详情"]: if d["关键词"] not in seen_kw: seen_kw.add(d["关键词"]) result["风险评分"] -= DEDUCTION[d["级别"]] * weight if d["修复建议"] and d["修复建议"] not in result["修复建议"]: result["修复建议"].append(d["修复建议"]) ``` ### Technical Analysis Whitelist status is assigned when a trusted-looking token appears anywhere in the attacker-controlled basename. There is no verification of the file's exact path, package identity, publisher, signature, or content hash. A file named `skill-vetter-backdoor.py` is therefore labeled as belonging to a known safe tool. The whitelist function also accepts `kw` but never uses it, so trust is not scoped to a specific finding. Additionally, the code calculates a reduced `deduction` for whitelisted files but never consumes that variable. The later scoring loop always applies the fu ...[truncated 1535 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scan_skills.py (reported line 47)May include surrounding context.

python
("chattr ",   "chattr 修改文件属性,需 root 权限"),
        (".bashrc",   ".bashrc 涉及 Shell 配置,确认来源可信"),
        ("/etc/passwd","读取系统账户文件,确认用途"),
        ("/etc/shadow","读取密码哈希文件,禁止在外部传输"),
        (".ssh/",     "涉及 SSH 密钥目录,确认用途后使用"),
    ],
    "低危": [

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough that ordinary requests such as asking for a security audit or risk analysis could invoke this skill unintentionally. In an agent environment, unintended activation can cause unnecessary scanning of workspace content, disclosure of file metadata, or interference with the user's intended task.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scan_skills.py (reported line 46)May include surrounding context.

python
|------|--------|------|
| 严重 | `eval(`, `exec(`, `os.system`, `subprocess.call`, `subprocess.run`, `__import__`, `importlib`, `pty.spawn` | -25 |
| 高危 | `requests.get`, `requests.post`, `urllib.request`, `http.client`, `socket.create_connection`, `curl`, `wget` | -20 |
| 中危 | `chmod`, `chown`, `sudo`, `chattr`, `ACL`, `passwd`, `shadow`, `/etc/passwd`, `.bashrc`, `.ssh/` | -15 |
| 低危 | `open(`, `write`, `base64`, `gzip`, `zlib`(单独出现不扣分,组合出现-5) | -5 |

### 评分标准

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 29)May include surrounding context.

md
|------|--------|------|
| 严重 | `eval(`, `exec(`, `os.system`, `subprocess.call`, `subprocess.run`, `__import__`, `importlib`, `pty.spawn` | -25 |
| 高危 | `requests.get`, `requests.post`, `urllib.request`, `http.client`, `socket.create_connection`, `curl`, `wget` | -20 |
| 中危 | `chmod`, `chown`, `sudo`, `chattr`, `ACL`, `passwd`, `shadow`, `/etc/passwd`, `.bashrc`, `.ssh/` | -15 |
| 低危 | `open(`, `write`, `base64`, `gzip`, `zlib`(单独出现不扣分,组合出现-5) | -5 |

### 评分标准

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file forces a specific language/locale for the skill description and usage instructions, and there is no indication that users may opt into another language or that the skill is intentionally region-specific. This can violate organizational language-choice policy when a skill is presented to a broader audience.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The listed trigger phrases are very broad generic requests for scanning, auditing, and risk analysis, so they are likely to overlap with normal user language and cause accidental or unintended invocation of the skill. In an agent environment, overly broad activation can route unrelated user requests into this skill and expose workspace contents or produce unexpected autonomous scanning behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings that force a specific language/locale for the script description and generated report path. The policy for SQP-3 applies to all file types and flags language constraints when the skill does not provide user opt-in or justify the locale restriction.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scan_skills.py (reported line 43)May include surrounding context.

python
"中危": [
        ("chmod ",    "chmod 修改权限,生产环境谨慎操作"),
        ("chown ",    "chown 修改所有者,需 root 权限"),
        ("sudo ",     "sudo 提权命令,确认必要性"),
        ("chattr ",   "chattr 修改文件属性,需 root 权限"),
        (".bashrc",   ".bashrc 涉及 Shell 配置,确认来源可信"),
        ("/etc/passwd","读取系统账户文件,确认用途"),

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions, trigger phrases, and output examples are defined only in Chinese, with no indication that the user may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L89声明该技能“仅提示风险,不自动禁止”,表述上强调不做阻断性处置;但L90又规定风险分<40时“不输出任何安装指引”,同时前文评分标准明确包含“禁止安装”“立即删除”等强烈处置建议。这些文档表述对技能是否只做提示、还是会产生实际阻断/劝阻性决策存在明显矛盾。

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scan_skills.py:18