Back to skill

Security audit

Update MD

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown documentation-template skill with no executable code; its main cautions are around storing infrastructure details and following Chinese-language templates.

Install only if you want a Chinese-language project documentation convention. When using the templates, avoid writing passwords, tokens, private keys, or sensitive host details into shared Markdown, and review any AGENTS.md doc-map update so it stays limited to documentation navigation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/doc-templates.md (reported line 108)May include surrounding context.

md
### 啟動
\`\`\`bash
docker build -t <image> .
docker run -d --name <container> --network <net> -p <port>:<port> --env-file .env <image>
\`\`\`

### 更新

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/doc-templates.md (reported line 115)May include surrounding context.

md
### 啟動
\`\`\`bash
docker build -t <image> .
docker run -d --name <container> --network <net> -p <port>:<port> --env-file .env <image>
\`\`\`

### 更新

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file includes imperative guidance in Chinese ("按需讀取") and elsewhere uses Chinese-only labels and descriptions, but does not state that the skill is intended for Chinese-speaking users or offer a language preference option. This can violate language/locale policy by implicitly forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples for required documentation structure and update rules use Chinese-only descriptors such as "精簡總覽,每 session 必讀" and "改動類型 | 需要更新". Because the skill presents these as standard mandatory conventions for all projects, it effectively enforces a locale-specific language without documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
1. Identify which files are affected by the change (use the update rules table)
2. Update only those files — don't touch unrelated docs
3. Update version number in OVERVIEW if it's a release
4. Add entry to HISTORY with date, version, and bullet points

## Creating a New Doc Set

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown deployment template instructs users to stop and remove a container as part of an update flow, which can affect service availability and system state. The surrounding text provides no warning about downtime, rollback considerations, or the impact of running these commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The canonical meanings for the status symbols are defined exclusively in Chinese, which may force downstream documentation into that language. The file does not mention that this is a region- or team-specific standard, nor does it offer a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document templates and embedded instructions are consistently written in Chinese, which may impose a language preference on users without opt-in or justification. There is no note that the skill is intended specifically for Chinese-speaking teams or that alternate language versions are available.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The deployment template asks users to record sensitive infrastructure access details such as server IP, username, path, and SSH command, and the database template includes connection metadata. The markdown does not warn users not to store secrets, private keys, or sensitive connection information in shared documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.