Back to skill

Security audit

账号切换器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local helper for listing, starting, and stopping accounts in a separate multi-account browser tool.

Install only if you trust the separate 多账号矩阵管理工具 and intentionally want an agent to list, launch, or close its local browser accounts. Review start and stop commands before use because they may interrupt active account sessions, and keep the API bound to localhost.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill explicitly supports starting and stopping browser accounts through a local HTTP API, which can change application state, terminate active sessions, or launch profiles without adequate user-facing warning in the description. Even though the target is a local service, these are state-changing actions with operational impact, so insufficient disclosure can mislead users or downstream agents into performing disruptive actions unexpectedly.

Static analysis

No suspicious patterns detected.