Back to skill

Security audit

multi-agent-team

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed project helper, but its broad automatic activation and under-scoped file-writing tool need review before installation.

Install only if you are comfortable with a globally enabled project assistant that can auto-activate on broad development wording. Keep it project-scoped if possible, disable autoInvoke unless needed, and do not pass untrusted values to spec_tools.py until path containment is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
spec_tools.py:142
Finding

Arbitrary File Overwrite Through Specification Path Traversal

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (84)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README_EN.md (reported line 863)May include surrounding context.

brew install python@3.11

text

### Q4: How to update skill?

**A**: Re-run installation script:
```bash

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/roles/solo-coder/DEVELOPMENT_TEMPLATE.md (reported line 127)May include surrounding context.

md
| 环境 | 服务器 | 数据库 | 配置文件 |
|------|--------|--------|----------|
| 开发环境 | 本地服务器 | 本地数据库 | .env.local |
| 测试环境 | 测试服务器 | 测试数据库 | .env.test |
| 生产环境 | 生产服务器 | 生产数据库 | .env.production |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/roles/solo-coder/DEVELOPMENT_TEMPLATE.md (reported line 129)May include surrounding context.

md
|------|--------|--------|----------|
| 开发环境 | 本地服务器 | 本地数据库 | .env.local |
| 测试环境 | 测试服务器 | 测试数据库 | .env.test |
| 生产环境 | 生产服务器 | 生产数据库 | .env.production |

### 6.2 部署流程

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example explicitly states that files are modified, added, deleted, and even '代码已提交' without showing any user approval gate, dry-run, or confirmation step. In an agent skill focused on autonomous multi-step execution, normalizing silent destructive changes can lead users to enable workflows that overwrite or remove project assets unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该贡献指南在“中文注释规范”部分明确要求“使用中文注释”,属于对贡献者输出语言的强制性约束。文件未说明这是可选项、未提供其他语言选项,也未给出明确的区域合规或项目范围理由,符合语言/locale policy violation 的判定条件。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Forcing output to the first detected language in mixed-language inputs can misinterpret user intent and be abused to steer the agent into an unintended language context. While not a direct code-execution flaw, it can degrade safety controls, user comprehension, and review accuracy in bilingual workflows where exact wording matters.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Architect trigger list includes broad phrases like code review, security check, and performance optimization that commonly appear in normal developer requests. Without explicit routing constraints or confirmation, the system may invoke a higher-privilege or differently-scoped role than the user intended, causing prompt-scope confusion and unintended authority transfer across agents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Product Manager trigger keywords are generic requirement-related phrases that can appear in ordinary planning or implementation conversations. This can cause unintended invocation of the PM role, leading to incorrect workflow execution, prompt injection surface expansion across roles, and misalignment between user intent and agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Test Expert activation phrases are broad enough to match routine development requests, especially terms like test plan, unit testing, and quality review. Ambiguous routing can shift execution into a testing-oriented prompt unexpectedly, which is dangerous in a multi-agent system because it alters tool use, priorities, and output constraints without clear user authorization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Solo Coder triggers are everyday development phrases such as implement feature, fix bug, and write code, so they are highly likely to over-match. In a multi-agent skill, this can silently route many requests into code-writing behavior, increasing the risk of unauthorized code changes, bypass of review-oriented roles, and confusion over expected safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all user-facing instructions, examples, and help text only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples introduce standalone tooling for spec management, codebase scanning, code-map generation, and project-understanding outputs that exceed the declared purpose of multi-agent task dispatch. This scope expansion can mislead users and downstream agents into invoking undocumented capabilities over local repositories, increasing the risk of unintended file access, data exposure, or over-privileged behavior without clear manifest disclosure or security review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example PRD includes 'User operation behavior' under tracking requirements without any accompanying privacy notice, consent requirement, data minimization guidance, or retention limits. In a skill that users may copy directly into product specifications, this normalizes behavior tracking as a default practice and can lead downstream implementations to collect telemetry in ways that violate privacy expectations or regulatory requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples use broad free-form prompts like architecture design, product definition, testing, and implementation requests that are similar to normal chat requests. In combination with automatic task recognition, this can cause the skill to activate on ambiguous user input and steer the session into high-authority workflows unexpectedly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The documented installation copies the skill into ~/.trae/skills/trae-multi-agent/, creating a persistent user-level artifact that remains active across sessions. In the context of a skill that can auto-invoke and orchestrate multiple roles, persistent installation increases the blast radius of accidental or unsafe behavior because the capability survives beyond a single project or session.

Content

Scanner excerpt · README.md (reported line 415)May include surrounding context.

bash
# 1. 创建技能目录
mkdir -p ~/.trae/skills/trae-multi-agent

# 2. 复制技能文件
cp -r /path/to/claw/.trae/skills/trae-multi-agent/* \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly documents a configuration with autoInvoke: true but does not describe narrow activation boundaries, approval gates, or trigger restrictions. For a multi-agent skill that can route broad natural-language prompts into role prompts and scripts, unconstrained auto-invocation increases the chance of unintended activation during ordinary conversation, amplifying prompt-injection and overreach risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README states the skill can be used directly and elsewhere describes automatic task identification and dispatching, but does not define strict activation boundaries. In an agentic environment, broad or implicit auto-activation can cause the skill to engage on unintended prompts, increasing the chance of inappropriate role switching, overreach, or execution of workflows on sensitive tasks.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README_EN.md (reported line 231)May include surrounding context.

md
### 4. Solo Coder / 独立开发者

**Responsibilities**: Write complete, high-quality, maintainable, and testable code

**Core Principles**:
- ✅ Zero Tolerance Checklist - 10 absolute prohibitions

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 422)May include surrounding context.

~/.trae/skills/trae-multi-agent/

3. Verify installation

ls -lh ~/.trae/skills/trae-multi-agent/SKILL.md

4. Restart Trae

text

Static analysis

No suspicious patterns detected.