Back to skill

Security audit

Skill Workflow-Composer

Security checks for vulnerabilities and agentic risk

Overview

This skill openly composes workflows by scanning installed and marketplace skills, with persistent or write actions gated by confirmation.

Install only if you are comfortable with the skill listing local installed skills and querying the skill marketplace when first used. Review any proposed automation, file write, publishing step, or reusable skill creation before confirming it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes broad generic phrases such as '技能组合', '技能编排', and '技能市场', which are likely to match ordinary user requests outside the user's intent to invoke this skill. In context, that is more dangerous because the skill's first-use behavior mandates scanning local installed skills and marketplace data, so accidental invocation can lead to unnecessary local enumeration and expanded data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level description does not clearly warn users that first use triggers scanning of local installed skills and marketplace queries. That matters here because the scan is mandatory on first execution and enumerates local skill inventories, which can reveal environment details, installed capabilities, project context, or other sensitive metadata without sufficiently informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L110 states the skill should reject 'any' modification to skill content during use. However, L111 explicitly permits users to supplement files under references/ and register them in the index, which is a modification to the skill package content. This is an active contradiction in the skill's own documented intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hard-requires bilingual user-facing output without checking the user's language preference. This can cause unnecessary disclosure or confusion in user-visible content, and in workflow/security contexts it may reduce clarity of warnings, confirmations, or consent text, increasing the chance of user misunderstanding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The validation checkpoint enforces bilingual output as a fixed compliance rule, which removes flexibility to present the clearest language for the user. In an orchestration skill that surfaces plans, risks, and confirmations, mandatory dual-language text can dilute critical instructions and create avoidable ambiguity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill mandates enumerating user-level and project-level local skill directories before any task, but does not require clear user notice or consent before inspecting locally installed skills. Even if limited to metadata, this behavior can reveal sensitive information about a user's tooling, projects, clients, or workflows and creates an unnecessary privacy exposure at session start.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow requires automatic platform skill-market searches on first session load without a user-facing warning that network/external access will occur. This can leak behavioral context, trigger unintended outbound requests, and violate user expectations in environments where external connectivity or metadata disclosure must be tightly controlled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "竞品日报" is broad and naturally overlaps with ordinary user language about competitor reporting. In a workflow-composition skill that scans markets, loads skills, and supports cross-session reuse, an overbroad trigger can cause accidental invocation of the wrong reusable workflow or collision with other installed skills, leading to unintended actions or data processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template ends with a very broad call to action, 'reply with a number to proceed,' which can cause accidental or ambiguous activation of the workflow-composition flow. In a skill that can chain multiple other skills and potentially reach write or automation steps later, overly permissive trigger language increases the chance of unintended execution paths and user confusion about consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill workflow catalog is written in Chinese and does not indicate that language selection is optional or user-configurable. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents all instructions, labels, and usage guidance only in Chinese. The policy for natural-language violations applies to all file types, and there is no indication that users can opt into this language or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L017 明确规定“面向用户文案中英成对”,L048 再次要求交付内容必须中英成对。这属于对输出语言/locale 的固定要求,但文档中没有说明可由用户选择语言偏好,也没有给出必须双语的合规性理由。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and surrounding template content are entirely written in Chinese, which establishes a default language for the skill artifact. Because the template does not offer an alternative language option or explain that the template is intentionally limited to a Chinese-specific context, it creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

SQP-3 适用于所有文件。L154-L162 明确以中文触发词‘竞品日报’和中文复用说明定义技能入口,但未说明是否支持其他语言或是否要求用户选择中文,可能构成未经用户选择的语言限定。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.