Back to skill

Security audit

学术文献解读(轻松幽默解读枯燥文献)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese academic paper explainer with minor scoping and temporary image-handling caveats, but no evidence of hidden or malicious behavior.

Before installing, be aware that the skill may trigger on broad "help me understand" requests and may copy paper images into a temporary folder during image analysis. Use it with papers and images you intend to share with the agent, and prefer explicit, user-provided folders.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation conditions are overly broad, especially the catch-all phrase "帮我理解 xxx", which can cause the skill to trigger on many unrelated requests. Overbroad triggers increase the chance of unintended invocation, context hijacking, or accidental processing of sensitive user content under the wrong skill behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs copying user-provided image files into a temporary directory using filesystem operations, but gives no user-facing notice, consent step, or safety constraints on paths and file handling. This can create unintended local file side effects, increase exposure of sensitive document images, and encourage unsafe handling of untrusted file paths or oversized inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.