Back to skill

Security audit

project-organization

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it deserves review because some file-moving and soft-delete commands are not clearly limited to the project folder.

Install only if you are comfortable giving the agent local file-organization authority. Use dry-run output first, confirm the exact project root, avoid arbitrary --dest or external --root combinations, and require an explicit confirmation before any --apply or --confirm operation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README defines buffer handling with a natural-language trigger like “读取 buffer”, which is broad enough to be invoked during ordinary discussion rather than an explicit user authorization step. In an agentic environment, this can cause unintended file enumeration or movement from the shared buffer area, especially because the feature is designed for automatic semantic routing of user-dropped files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow description says the agent can read the buffer and automatically classify and relocate files, but it does not define strict trigger conditions, required confirmations, or disallowed ambiguous phrasings. That creates a prompt-to-action gap where casual language may be interpreted as authorization, leading to unintended processing, disclosure, or modification of files in a long-lived project workspace.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill describes and encourages filesystem reads, writes, moves, soft-deletes, and environment-variable-based path resolution, but it does not declare an explicit tool/permission scope. That creates an authorization ambiguity: an agent may invoke the skill in contexts where users and reviewers cannot easily tell that broad file operations are expected, increasing the risk of unintended modification of local project trees.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s natural-language description and invocation guidance are presented as Chinese-only instructions, including the quoted command phrase the user is expected to say to the AI. There is no indication that the user may choose another language or that the locale restriction is intentional and justified, which creates a language-policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and overlap with normal conversation about project management, directory cleanup, or reading a buffer. Because this skill can perform file moves and deletions-to-trash, accidental activation could cause the agent to propose or carry out organizational changes in the wrong context or on the wrong directory tree.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language descriptions and user-facing messages entirely in Chinese, including the module docstring and CLI help/output guidance. Under the stated policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argparse description, option help text, and emitted error message are all presented only in Chinese. This creates a natural-language locale restriction for users of the script without any mechanism to select language or evidence of a documented, justified regional limitation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The take command accepts --dest and returns Path(args.dest).expanduser() without constraining the destination to remain under the resolved project root. When --apply is used, inbox content can be moved anywhere the invoking user can write, which defeats the skill’s stated project-bound organization model and can be abused for unintended file placement or data exfiltration into arbitrary local paths. In this project-organization context, that is more dangerous because the tool is meant to automate classification of user-dropped files, so an agent using it could silently move material outside the managed tree.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file’s natural-language guidance is entirely in Chinese, including operational descriptions and conventions, with no indication that users may choose another language. Per the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The soft_remove helper performs filesystem moves into a trash/replaced area without any built-in confirmation, disclosure, or guardrails about what is being relocated. In the context of a project-organization skill that automatically classifies and reorganizes files from a shared buffer, this increases the chance of unintended file displacement, hidden data movement, or operator confusion, especially if higher-level code invokes it on user content without explicit review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented trigger phrases are numerous and generic enough that they may match ordinary user conversation, causing the skill to activate in contexts where the user did not intend project-reorganization behavior. In this skill, unintended activation is more dangerous because it is tied to file classification and movement workflows, which can lead to accidental reorganization of user data or preparation for subsequent file operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire README template content is written in Chinese, including operational instructions and warnings, with no indication that language choice is optional or that the skill is intended only for a Chinese-speaking context. This can violate language/locale policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill description is written in Chinese and does not indicate that other languages are supported or that Chinese is required for a justified region-specific purpose. This creates a natural-language locale policy concern because it effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains natural-language instructions, descriptions, and help text exclusively in Chinese, including the module docstring and usage examples. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The stated purpose emphasizes organizing project files already associated with the long-lived project and semantically routing content between buffer/ and projects/. cmd_deliver and cmd_add accept arbitrary filesystem source paths and copy or move them into the buffer, making the script a more general cross-filesystem import/export tool than the manifest clearly justifies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents its instructions entirely in Chinese, which can impose a language choice on users without offering an opt-in or documenting a justified locale restriction. The policy specifically calls for flagging language or locale constraints when they are forced without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and maintenance note are written only in Chinese, which implies a fixed language/locale for the skill content. Under the stated policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section headings and placeholder instructions are written entirely in Chinese, which establishes a default language requirement for downstream skill documentation. There is no visible opt-in, alternative language option, or statement that this template is intended only for a specific locale or region.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.