Back to skill

Security audit

Skill Combo Recommender

Security checks for vulnerabilities and agentic risk

Overview

This is a static skill/workflow recommender with a visible installer; the main caution is that some suggested workflows involve social posting, proxies, or file-changing tools.

Reasonable to install if you want a static workflow recommender. Review the installer first because it overwrites any existing same-named skill directory and may create a CLI symlink. Treat recommendations involving proxies, multi-account social media, scheduled publishing, finance, or file organization as prompts for manual review, not approval to run them automatically.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README promotes a workflow that includes proxy IP setup and automated social-media publishing but does not warn users about privacy exposure, account suspension risk, terms-of-service violations, or jurisdictional/legal implications. In a skill repository, presenting this as a normal recommended workflow can encourage unsafe or non-compliant use, especially by less experienced users.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The README advertises file-organization automation without warning that these workflows may move, rename, or otherwise alter user files. Users may assume the tooling is read-only and unintentionally cause data loss, overwrite conflicts, or disruption of existing directory structures.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description is broad enough to trigger on ordinary conversational requests such as asking generally what skills to use or how to optimize a workflow. This can cause unintended skill activation, leading the agent to route users into automation or platform-specific workflows they did not explicitly request, including recommendations involving publishing, proxies, or financial tooling.

Ssd 4

Medium
Confidence
91% confidence
Finding
The preset workflow explicitly recommends combining a Xiaohongshu content workflow with a 'multi-account proxy pool manager' and scheduled publishing, which facilitates evasion of platform controls and scaled multi-account operations. In skill context, this is more dangerous than a generic proxy reference because it operationalizes account farming or policy-violating automation as a recommended workflow step.

Static analysis

No suspicious patterns detected.