Back to skill

Security audit

Eno Skills

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only frontend architecture review skill whose behavior is disclosed and aligned with analyzing project structure, dependencies, build setup, and maintainability.

Install this if you want Chinese-first frontend architecture review guidance. Be aware that it may activate on broad frontend terms and may ask you to share project structure or config snippets; only provide files you are comfortable having analyzed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · frontend-arch-skill.md (reported line 207)May include surrounding context.

md
| Tree-shaking | 2 分 | sideEffects 配置正确 |
| 路径别名 | 1 分 | @ 或 ~ 别名配置 |
| Source Map | 1 分 | 生产环境关闭或使用 hidden-source-map |
| 环境变量 | 1 分 | .env 文件 + cross-env / dotenv |
| 缓存策略 | 1 分 | contenthash 文件名 |

**Vite 项目检查清单:**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · frontend-arch-skill.md (reported line 219)May include surrounding context.

md
| Tree-shaking | 2 分 | sideEffects 配置正确 |
| 路径别名 | 1 分 | @ 或 ~ 别名配置 |
| Source Map | 1 分 | 生产环境关闭或使用 hidden-source-map |
| 环境变量 | 1 分 | .env 文件 + cross-env / dotenv |
| 缓存策略 | 1 分 | contenthash 文件名 |

**Vite 项目检查清单:**

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase list includes generic terms such as component design, build config, and monorepo that may appear in ordinary conversation or unrelated review requests, causing the skill to activate when the user did not explicitly ask for this architecture-analysis behavior. In a prompt-based skill system, over-broad activation can unexpectedly inject long instruction sets and alter assistant behavior, which is a real prompt-routing security and safety issue even without code execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation keywords are very broad and include common frontend terms like webpack, vite, monorepo, and component design. This can cause the skill to activate in conversations that only mention these topics casually, leading to unintended prompt takeover, irrelevant architectural judgments, or disclosure requests for project structure/configuration beyond what the user intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The intent-based activation rules are underspecified and rely on subjective interpretation of whether a user is asking if a choice is 'reasonable' or 'how to optimize'. In an agent system, ambiguous boundaries increase the chance of misrouting, causing the skill to engage when the user wanted a narrow answer and potentially steering the interaction into broad project analysis or unnecessary data collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is entirely written as a Chinese-only rule engine and its output templates, prompts, and follow-up guidance all assume Chinese responses without offering a language fallback or stating a justified locale restriction. In a general-purpose agent skill, this can cause user intent mismatch, reduce transparency, and create unsafe interaction failures when users cannot understand requests for sensitive project data or remediation advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The document presents the skill primarily in Chinese, with only a brief English subtitle, and does not clarify whether outputs or interaction language follow the user's preference. Because locale and language behavior are part of policy scope, the absence of an explicit user-choice statement creates a risk that the skill may default to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The document title, metadata, and most operating instructions are in Chinese, which can imply a default language behavior without explicit user opt-in. Although English trigger examples are included, the file does not clearly state that output language will follow user preference or that users may choose their locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.