Back to skill

Security audit

HiFi Review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed HiFi-review workflow with local analysis scripts and evidence guardrails; the scanner concerns mostly reflect false positives or purpose-aligned review instructions.

Before installing, note that the workflow may fetch public reviews/pages during use and may run bundled Python scripts on measurement files you provide. Prefer a trusted or pinned install source outside ClawHub, and pay attention to generated warnings about missing rig/target metadata because they affect audio-analysis reliability.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (37)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · CHANGELOG.md (reported line 20)May include surrounding context.

md
outputs, 5 witnesses, 6 fixtures): 0 verdict changes.
- **F05 missing inputs become gaps, not verdicts** (accuracy-guardrails "Never
  invent"). `source_analyze.py --target-z 32` without sensitivity/power returned
  `hiss_risk low`, `drives_adequately false`, `max_spl_db 0.0`, no warning. Now those
  verdicts stay `null` / `"unknown"`, the numbers are omitted, and a `missing_input:*`
  warning names the gap; `source-analysis.schema.json` allows it; `source-gear-eval.md`
  says to report it as a `gap`. Goldens and the recorded case-3 arm output replay

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose suggests a skill that analyzes audio gear and produces objective assessment content. The supplied code does not assess gear performance or compare HiFi devices; instead, it checks whether a review text meets preset long-form requirements and whether optional supporting JSON conforms to a schema. This is a materially different primary purpose: review-output QA rather than HiFi evaluation itself. The behavior is related to the broader review workflow, but the code chunk’s actual function is structural validation, not evidence-based gear assessment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is focused on one specific analytic task: inferring which predefined target curve a transducer was tuned toward based on frequency-response data from a known measurement rig. That is materially narrower and different from the declared purpose of providing broad, objective evaluations of HiFi gear, including DACs/amps/DAPs, as bilingual evidence-traced verdicts. There is no indication here of bilingual output, source citation/tracing, A/B review logic, or support for source gear evaluation. While target inference could be a supporting subroutine within a larger review system, this chunk’s primary behavior is specialized classification against target profiles, which is not accurately represented by the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is about objectively reviewing HiFi equipment and producing sound-quality assessments. The actual code does nothing related to audio analysis, HiFi gear, bilingual review generation, A/B comparison, or evidence tracing. Instead, it is a general-purpose JSON/schema validation utility that reads local files and validates structured data. This is a materially different primary purpose, so it is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
7. **Synthesize** — class-discriminated profile + render: compact bilingual summary OR a **~4000字 长文** (`rules/longform-review.md`); both render only from evidence; tag claims `measured|consensus|prior` + confidence; gaps "证据不足". → `rules/literary-rendering.md`, compare → `rules/comparison-mode.md`.
8. **Self-verify** — source class: first re-read every claim about what is or is not heard against the audibility judgment card in `rules/source-gear-eval.md`. Then `python3 scripts/validate_output.py <out.json>` (schema + traceability-structure gate; what exit 0 proves → `rules/accuracy-guardrails.md`); emit `trace`; never pass a FAIL. If it cannot run, write "self-verify not run" in `trace`/`gaps`.

Always obey `rules/accuracy-guardrails.md`: never invent a dB/curve; flag
incompatible rig/target comparisons; record dissent.

## Modules

Hidden Instructions

High
Category
Prompt Injection
Confidence
96% confidence
Finding

The HTML comments contain operative instructions to copy blocks, use only certain evidence, strip comments before delivery, target a specific output size, and run a verification script. Hidden operational directives are dangerous because they can steer model behavior in ways not visible to downstream reviewers and can smuggle process requirements that the agent may prioritize over higher-level controls.

Content

Scanner excerpt · assets/longform-template.md (reported line 1)May include surrounding context.

md
<!-- Long-form 评测长文 skeleton. Copy the matching block, fill each section from the
     evidence set ONLY. Strip these HTML comments before delivering. Target ~4000字
     (CJK), band 3500–4500. Run scripts/check_longform.py to verify. -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This hidden comment prescribes detailed content-generation behavior, including section structure, evidence class labeling, measurement frameworks, and exact topical coverage. Even if editorial in nature, embedding these directives in comments creates non-transparent prompt injection surface and can cause the agent to follow concealed instructions instead of visible policy or user intent.

Content

Scanner excerpt · assets/longform-template.md (reported line 10)May include surrounding context.

md
# 《<设备名>》客观评测长文

## 一、开篇与定位
<!-- ~400字, 先验/规格: 类型、定位价位、单元构型、品牌家族/前作血缘. 标注 [先验] -->

## 二、客观测量
<!-- ~700字, 实测: 测量台(711/GRAS)与对齐 target(Harman IE/OE/IEF/DF)、对齐方式、

Hidden Instructions

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This duplicate hidden-instruction instance at the same line carries the same risk: concealed behavior-shaping content that directs output framing and analysis details. Even when non-malicious, duplicate hidden directives increase ambiguity and make review and enforcement harder.

Content

Scanner excerpt · assets/longform-template.md (reported line 17)May include surrounding context.

md
8 频段量感向量逐条、整体偏离. 给出 fr_analyze 的 dev_db/quanta. 标注 [实测] -->

## 三、三频解析
<!-- ~900字, 实测: 低频(sub/mid_bass) / 中频(lower/center/upper) / 高频(treble/air)
     各自相对 target 的量感与听感映射;窄峰/凹陷单列为 flagged feature. -->

## 四、风格与调音

Hidden Instructions

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This duplicate hidden-instruction instance at the same line carries the same risk: concealed behavior-shaping content that directs output framing and analysis details. Even when non-malicious, duplicate hidden directives increase ambiguity and make review and enforcement harder.

Content

Scanner excerpt · assets/longform-template.md (reported line 17)May include surrounding context.

md
8 频段量感向量逐条、整体偏离. 给出 fr_analyze 的 dev_db/quanta. 标注 [实测] -->

## 三、三频解析
<!-- ~900字, 实测: 低频(sub/mid_bass) / 中频(lower/center/upper) / 高频(treble/air)
     各自相对 target 的量感与听感映射;窄峰/凹陷单列为 flagged feature. -->

## 四、风格与调音

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog states that rig/target compatibility is 'enforced', but later entries acknowledge the protection only works when rig metadata is provided and may otherwise be skipped. This creates a misleading security/correctness claim that can cause users or downstream agents to over-trust comparison results and accept invalid cross-rig conclusions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The changelog states a long-form output mode is "Chinese-primary," which is a locale/language constraint expressed in natural language. There is no indication here that users can choose their preferred language or explicitly opt into that default, so this appears to force a language preference.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.en.md (reported line 18)May include surrounding context.

md
**When to use** — "客观评价这条耳机" · "对比 A 和 B 的声音" · "这个 DAC 素质如何 / 推得动吗"; or call `/hifi-review`.
**Not for** — buying / 价格 recommendations; EQ tuning; speakers; non-audio.

**Install** — `npx skills add VincentJiang06/skills` (or `cp -R skills/hifi-review ~/.claude/skills/`).

**Known limitations** — `validate_output.py` checks structure only (schema, every claim traced to a listed source, claims with a technicality `attribute` tagged consensus — it reads the tag, not the sentence, so an untagged technicality claim slips past it); it does not judge whether a claim is justified (e.g. an audible-difference claim — that is the Step 8 self-read against the judgment card). The L1 goldens are regression baselines frozen by the engines on synthetic curves: they prove determinism and no regression, not accuracy. Known gaps still open in 1.1.1: a coloration / sibilance id such as `coloration_high` tagged measured still passes; `compare.py` still returns `comparable: true` when a rig is missing or misspelled and records the skipped guard only in `warnings` — read the warnings, not the flag, before calling two curves comparable. Two-arm check (3 cases, vs bare Opus 5.5): the skill was better in 2 (the edge is rig / target matching), tied in 1, worse in 0.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install instruction uses npx skills add VincentJiang06/skills without pinning a specific package version or immutable reference. That creates a supply-chain risk: users may fetch whatever the latest published package resolves to at execution time, including a compromised or malicious update, and npx executes code during install.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

md
**什么时候用** —— 「客观评价这条耳机」·「对比 A 和 B 的声音」·「这个 DAC 素质如何 / 推得动吗」;也可用 `/hifi-review` 显式调用。
**不适用** —— 买买买 / 价格推荐;EQ 调音;音箱;非音频。

**安装** —— `npx skills add VincentJiang06/skills`(或 `cp -R skills/hifi-review ~/.claude/skills/`)。

**已知局限** —— `validate_output.py` 只查结构(schema、每条结论都挂在已列出的来源上、`attribute` 为技术力的结论标为共识——它读标签不读句子,没打技术力标签的结论会漏过),不判断结论是否站得住(如「可闻差异」是否成立,这由 Step 8 按判断卡自读);L1 golden 是引擎在合成曲线上自己冻结的回归基线,只证明确定性与不回退,不证明准确。1.1.1 仍未修的已知缺口:`coloration_high` 这类染色 / 齿音 id 标成 measured 仍会放行;`compare.py` 在耦合腔(rig)缺失或拼错时仍给出 `comparable: true`,只在 `warnings` 里记一条——判断两条曲线能否比较要看 warnings,不能只看这个标志。两臂对照(3 例,对裸 Opus 5.5):2 例本 skill 更好(优势在耦合腔 / 目标曲线匹配),1 例持平,0 例更差。

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

md
**什么时候用** —— 「客观评价这条耳机」·「对比 A 和 B 的声音」·「这个 DAC 素质如何 / 推得动吗」;也可用 `/hifi-review` 显式调用。
**不适用** —— 买买买 / 价格推荐;EQ 调音;音箱;非音频。

**安装** —— `npx skills add VincentJiang06/skills`(或 `cp -R skills/hifi-review ~/.claude/skills/`)。

**已知局限** —— `validate_output.py` 只查结构(schema、每条结论都挂在已列出的来源上、`attribute` 为技术力的结论标为共识——它读标签不读句子,没打技术力标签的结论会漏过),不判断结论是否站得住(如「可闻差异」是否成立,这由 Step 8 按判断卡自读);L1 golden 是引擎在合成曲线上自己冻结的回归基线,只证明确定性与不回退,不证明准确。1.1.1 仍未修的已知缺口:`coloration_high` 这类染色 / 齿音 id 标成 measured 仍会放行;`compare.py` 在耦合腔(rig)缺失或拼错时仍给出 `comparable: true`,只在 `warnings` 里记一条——判断两条曲线能否比较要看 warnings,不能只看这个标志。两臂对照(3 例,对裸 Opus 5.5):2 例本 skill 更好(优势在耦合腔 / 目标曲线匹配),1 例持平,0 例更差。

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx skills add VincentJiang06/skills without pinning an exact package/version or commit. That creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed at install time, and npx commonly executes downloaded code immediately. In the context of an install command in documentation, this is a real risk because users may copy-paste it verbatim.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown explicitly requires output to be bilingual in Chinese and English. This is a natural-language locale policy constraint with no user opt-in or alternative language choice, which can violate organizational language-choice policies.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation, but the manifest does not define tight activation boundaries beyond a broad HiFi-review description and default prompt. This can cause the agent to trigger the skill in loosely related conversations, exposing user content to an external evaluation workflow or causing unintended authoritative responses outside the intended scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template hard-requires Chinese long-form output and a specific length band without any user-language choice or opt-in. This can override user preference and system/application expectations, causing unwanted behavior or policy non-compliance, though it does not by itself enable code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown includes a hardcoded requirement using the Chinese character '字' in the statement about what check_longform.py validates. This indicates a locale/language-specific constraint in the skill guidance without offering user choice or documenting an opt-in, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file explicitly requires output to be rendered in both Chinese and English and specifies Chinese-first ordering. This imposes a language/locale behavior on users without offering a choice or explaining a region-specific requirement, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rule hard-requires Chinese-primary output for long-form reviews without indicating any user-language override or consent path. This can cause the agent to ignore a user's preferred language, reducing usability and potentially causing misunderstandings, but it does not appear to create a direct security compromise such as code execution, data exfiltration, or privilege misuse.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains operational guidance in mixed Chinese/English terms such as '声场/soundstage', '结像/imaging', and later uses additional Chinese-only phrases. Under the natural-language policy rule, forcing or assuming a specific language/locale without user opt-in can be a policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

Lines in this section include terms like '科fi/hufi' and '量感' embedded in normative instructions, which can impose a language expectation on users or maintainers. Because the file does not state that it is region-specific or provide an alternative language path, this may violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.