Back to skill

Security audit

Agent News

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it gives agents high-impact publishing and production-server powers using unsafe defaults that require human review.

Review before installing or using this skill. Do not rely on the built-in API key, do not send credentials over HTTP, and do not let an agent run the root SSH, deployment, PM2 startup, or delete commands without explicit human authorization and a least-privilege deployment design.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:70
Finding

Hardcoded API Credential Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:113
Finding

Mutable Remote Repository and Dependency Code Executed Without Integrity Pinning

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:106
Finding

Production Deployment and Maintenance Performed as Root

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:151
Finding

PM2 Startup Registration Creates Cross-Session Persistence

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill directs the agent to transmit requests to an external host by default (http://118.145.101.171) and elsewhere includes authenticated write operations using a fallback API key. External transmission to a hard-coded remote service is risky in agent environments because it can leak operational data, trigger unintended network actions, and normalize contacting an untrusted endpoint without validation.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

接口操作(curl示例)

获取文章列表

bash
curl ${BASE_URL:-http://118.145.101.171}/api/articles
# 搜索文章
curl "${BASE_URL:-http://118.145.101.171}/api/articles?search=关键词"
# 按分类过滤

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation provides create, update, and delete API examples, including a destructive DELETE call, without any confirmation workflow, dry-run guidance, or warnings about irreversible changes. In an agent context, this increases the risk of accidental or unauthorized modification of published content if the agent operationalizes examples directly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes direct production administration steps using ssh root@118.145.101.171, git pull, and PM2 lifecycle control. For a content-publication skill, embedding root-level server operations materially expands the agent's authority and could enable unauthorized infrastructure changes, persistence, or service disruption if followed automatically or with insufficient review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The production deployment section instructs privileged access and service-management actions such as SSH as root, build/deploy, and PM2 start/delete, but gives no safety boundaries or approval requirements. This can cause service outage, unintended deployment, or unauthorized system changes if an agent treats the instructions as routine operational guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language content of the skill is written exclusively in Chinese and does not offer an alternative language or indicate that the user can choose their preferred locale. This can violate a language/locale policy when a specific language is forced without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.