Back to skill

Security audit

Code Project Auto Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill reads a user-specified code project and generates a Chinese project summary document, with no evidence of hidden network access, persistence, credential use, or destructive behavior.

Install this only if you are comfortable letting it inspect local project folders and create a markdown summary file. Avoid pointing it at repositories containing secrets or private business code unless that analysis is intended, and expect Chinese output unless you modify the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises scanning arbitrary local code directories but does not warn users that the skill will read local files and analyze repository contents. This lack of disclosure can lead users to invoke the skill without understanding the privacy implications, especially if sensitive source code, credentials, internal documentation, or proprietary logic are present in the scanned path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary conversation about codebases, which can cause the skill to activate when the user did not explicitly intend to scan a local directory. In this skill’s context, unintended activation matters because the skill is designed to read arbitrary local project paths and summarize their contents, increasing the chance of unexpected local file access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill name, description, and usage are written entirely in Chinese and describe generation of project introduction documents without indicating that output language is selectable by the user. This creates a locale-policy concern because the skill appears to default to a specific language without opt-in or justification as a region-specific tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad natural-language requests such as analyzing a project or explaining a codebase, which can overlap with ordinary conversation and cause the skill to activate when the user did not explicitly intend to invoke it. In a skill that reads local code directories and generates derived documentation, unintended invocation can expose repository contents or steer the assistant into higher-privilege file access workflows than the user expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code generates user-facing documentation and command-line messages exclusively in Chinese, including the produced markdown and usage text. Because the file provides no user opt-in, locale selection, or documented region-specific justification, it violates the language/locale policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.