Back to skill

Security audit

weimingli-123

Security checks for vulnerabilities and agentic risk

Overview

This is a broad coding-assistant skill with disclosed optional local guardrail hooks and project memory; I did not find hidden exfiltration, destructive behavior, or deceptive payloads.

Install this only if you want a powerful coding workflow that may maintain project memory and optional persistent local hooks. Run the deployer in dry-run first, review every target config, avoid --scope user or both unless you want hooks across all projects, and regenerate hooks.installed.json for your own machine.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (127)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an advanced full-stack engineering expert skill focused on analysis, design, coding assistance, governance, and technical guidance. The supplied code does something materially different: it is an operational filesystem hook that automatically backs up existing source/config files before edits. This is not a supporting implementation detail of an expert coding assistant; it is a distinct utility with a different primary purpose, trigger model, and resource access pattern. The description does not disclose automatic hook execution, stdin-driven tool interception, or local file backup/rotation behavior. Therefore the description does not accurately represent the code chunk's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a general-purpose senior full-stack engineering expert skill, but the actual code implements a very specific cross-tool hook for 'learning capture' and recurrence prompting. Its primary behavior is not API design, coding assistance, architecture guidance, or broad engineering expertise; instead it passively processes hook event payloads, inspects tool output/user input, reads a local memory index file, and prints reminders about recording incidents. This is a materially different purpose with undeclared triggers/resources (stdin hook events, PROJECT_ROOT, .ai-memory/error_index.md). Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a comprehensive full-stack programming expert skill with wide engineering and governance capabilities across Java, PHP-CMS, frontend, MySQL, and project-level advisory functions. The supplied code does not implement those capabilities. Instead, it is a specialized Python hook for scanning PHP CMS files for known risky patterns after tool use. Its primary purpose is security linting/static pattern detection, not general software engineering assistance. This is a material description-behavior mismatch because the actual code is much narrower and substantively different in function from the declared broad expert assistant role.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a general-purpose senior full-stack coding expert with many advisory and generation capabilities. The supplied code, however, implements a narrow automated compliance/checking hook for detecting leftover debug statements in source files. This is not just an implementation detail of the declared expert skill; it is a materially different primary purpose and trigger model. The code is invoked globally as a PostToolUse hook, processes stdin JSON, reads files from disk, and scans them with regexes. None of that behavior is represented in the declaration, which suggests an interactive programming expert rather than an automated debug-residue detector. Therefore the description does not accurately represent the actual code behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a general-purpose senior full-stack engineering expert skill with many advisory and coding capabilities. The supplied code instead implements a narrow automation hook for dependency-change detection and vulnerability-scan prompting. This is a materially different primary purpose and trigger model: automatic post-tool execution based on changed file paths rather than an explicitly invoked broad engineering assistant. While security/threat-modeling themes are mentioned in the description, they do not accurately represent this concrete hook behavior, inputs, and outputs. Therefore the description does not accurately represent what the code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a very broad full-stack expert assistant skill for software engineering tasks. The supplied code does not implement those capabilities. Instead, it is narrowly focused on a post-tool-use deduplication guard for an error knowledge base: it activates on file write events, inspects paths, reads error_index.md, compares content tokens against indexed triggers, and emits warnings about possible duplicate ERR entries. This is a materially different primary purpose and introduces undeclared behavior around hook-based monitoring of memory files. While such functionality could be part of a larger engineering system, this code chunk itself does not match the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a general-purpose high-level full-stack programming expert covering a very wide range of engineering activities. The supplied code does not implement those capabilities. Instead, it performs a specific operational hook: after a tool write action, it loads an error index from project memory, matches keywords against the target filename and content, skips memory-maintenance writes, and emits a non-blocking reminder. This is a materially different primary purpose and includes concrete filesystem access and hook-triggered monitoring behavior that are not reflected in the declared description. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a general high-level full-stack engineering expert skill, but this code implements a very specific automation hook: after code files are written, it inspects project structure, checks for cached knowledge-graph artifacts, invokes another script to query upstream dependencies, and sends a concise impact summary to the agent. That trigger and behavior are materially different from the declared purpose. This is not just an implementation detail of a coding assistant; it is an undeclared operational hook with filesystem inspection, subprocess execution, and automatic post-write dependency analysis. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code does not implement a full-stack programming expert assistant or any of the broad development, review, documentation, planning, or governance capabilities described. Instead, it performs a narrow operational control: intercepting tool use and preventing writes to specific directories based on file paths. This is a materially different primary purpose and an undeclared capability involving global hook-based enforcement over filesystem write actions. While the declared description mentions security/governance themes at a high level, this code is specifically a guardrail script, not an expert programming skill interface, so the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents an interactive software engineering expert skill covering coding, review, architecture, and process guidance. The supplied code does not implement any of those core capabilities. Instead, it implements a global PreCompact hook that inspects the local filesystem, derives project context from recent file changes and plan/memory files, and persists a handoff snapshot. This is a materially different primary purpose and includes resource access behaviors (reading and writing project files/directories) not reflected in the description. The trigger model is also inconsistent: the description mentions explicit @ invocation support, while the code is an automatic hook executed before context compression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a general-purpose senior full-stack engineering expert skill with advisory and coding-assistance capabilities across many domains. The actual code does not implement any of those expert functions. Instead, it performs a specific operational task: processing a hooks.json template into a concrete installed configuration file using local paths and file I/O. This is a materially different primary purpose and includes concrete configuration-installation/file-manipulation behavior not reflected in the description. There is no evidence in the code of API design assistance, bug diagnosis, code review, testing, performance analysis, strategy, or the other broad expert capabilities described.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a comprehensive full-stack expert skill with many advisory and generation capabilities across multiple technologies, plus explicit invocation semantics. The supplied code does not implement that general assistant behavior. It is a specialized hook for Java version compatibility checks only. Its primary purpose, trigger mechanism, and resource access pattern are materially different from the declaration: it automatically runs after tool usage, inspects filesystem build config files, and emits warnings based on regex feature detection. This is not merely an implementation detail of the declared expert skill; it is a substantially different and much narrower behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code does not implement a general-purpose full-stack programming expert assistant. Instead, it is a narrowly scoped automation hook that triggers after writing source files and performs syntax validation for .php, .java, and .py files. This is a materially different primary purpose and trigger model from the declared description, which emphasizes broad engineering expertise and explicit @ invocation. The code also executes local tooling (php, javac, python) to inspect files, which is an operational capability not described in the skill summary. While syntax checking could be loosely related to code quality, the actual behavior is specific, automatic, and hook-based, making the description inaccurate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a general-purpose high-level software engineering expert skill, but the supplied code does not implement any programming-expert assistance functions such as code generation, review, debugging, design, testing, or technical strategy. Instead, it performs a specific operational housekeeping task: pruning/archiving old memory folders from a local .ai-memory store after tool use. This is a materially different primary purpose and includes undeclared filesystem access and mutation capabilities. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description presents a very broad interactive engineering expert skill, but the supplied code implements a specific automated compatibility scanner hook for PHP files. Its primary purpose is not code generation, review, architecture, or full-stack assistance; it is a post-tool static pattern checker for a small set of PHP 8 migration issues. It also has an undeclared automatic trigger model and reads file contents from disk based on tool input, which is materially different from the declared no-trigger/no-permissions profile. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code does not implement a general full-stack programming expert assistant. Instead, its primary purpose is policy enforcement: blocking edits to core code directories unless an active plan file exists. This is a materially different behavior from the declared description, which presents an advisory/coding expertise skill rather than an operational guard hook. The hook is also implicitly triggered globally on tool use, whereas the description says it supports explicit @ invocation and provides no indication of automatic filesystem-enforcement behavior. Therefore the description does not accurately represent the actual code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a general-purpose full-stack expert assistant skill with broad advisory and coding capabilities. The supplied code does not implement such an assistant. Instead, it implements a narrowly scoped enforcement hook that automatically scans attempted PHP file writes and blocks them on policy violations. This is a materially different primary purpose and trigger model: it is an always-on precheck for write tools, not an explicitly invoked expert skill. The code also performs undeclared operational capabilities such as reading tool input, diffing against existing files, locating PHP executables, invoking php -l, and denying writes with structured rejection reasons. These behaviors are not merely supporting details of a coding expert; they define a different kind of skill focused on guardrail enforcement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a material mismatch between the declared description and the actual code. The description presents a general-purpose, high-level full-stack engineering expert skill with wide-ranging advisory and coding capabilities. The code instead implements a narrow automation hook for recurrence-based promotion suggestions from local error ledger markdown files. Its primary purpose, resources accessed, and interface are all much more specific than declared. While one could loosely relate this to engineering discipline or project memory, the code does not provide the broad expert behaviors claimed; it is a specialized file-processing CLI script. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a general-purpose senior full-stack programming expert skill. The supplied code does something much narrower and different: it implements an automated hook for validating cross-file step-number references in skill documentation after certain file edits or commands. This is a materially different primary purpose and includes undeclared behavior such as trigger-based hook execution, subprocess invocation, and JSON context emission. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a general-purpose, high-level full-stack engineering assistant covering coding, review, design, testing, governance, and related advisory functions. The supplied code does not implement any of those broad assistant capabilities. Instead, it implements a narrow security scanning hook: after tool use, it automatically inspects written .php files for regex-patterned secrets and sensitive logging behavior and emits warnings. This is a materially different primary purpose, uses undeclared resources (stdin event payload and filesystem file reads), and has an automatic global hook trigger that does not match the declared '@ explicit invocation' model. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

描述强调的是一个通用的软件工程与编程专家型技能,覆盖设计、生成、审查、测试、治理等大量高层能力;但代码并未实现这些能力。代码的核心用途非常具体:作为全局 PostToolUse 钩子,在源码写入后自动扫描 PHP/Java 文件中的安全红线并打印告警。这属于安全扫描/审计自动化工具,而不是通用全栈专家助手。且描述中未说明它会作为全局 hook 被动触发,也未说明会读取本地文件进行静态分析。因此,代码的实际主要行为与声明用途存在实质性不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared description presents a general-purpose high-level full-stack engineering expert with many advisory and coding capabilities across multiple domains. The supplied code does not implement any such broad assistant behavior. Instead, it is a narrowly scoped hook that inspects a written source file for a specific SQL anti-pattern ('SELECT *') and prints warnings. Its primary purpose, trigger model, and operational behavior are materially different from the declared expert skill description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a general-purpose senior full-stack engineering expert/assistant, covering a wide range of advisory and coding tasks. The supplied code instead implements a narrowly scoped automated security check: a global hook that inspects edited files for SQL injection patterns using regexes. This is not just an implementation detail of a broad expert assistant; it is a materially different operational behavior with its own trigger model (automatic hook execution), resource access pattern (reads files from disk based on tool input), and security-linting purpose. While security is mentioned in the description at a high level, the concrete behavior here is a specialized scanner and global enforcement hook, which is not accurately conveyed by the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码的主功能与声明的技能定位明显不符。该脚本只处理特定目录下 Markdown 文档与 reference 文件之间的步骤编号引用一致性,属于窄范围的文档校验工具,而非一个广义的全栈编程专家技能。它没有实现声明中列出的多数能力,也没有呈现相应的交互、分析、生成或审查功能。虽然这种检查可被视为工程文档维护中的辅助工具,但不足以代表声明中的主要目的,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description promises a comprehensive full-stack expert capability across many software engineering domains, with explicit @ invocation support. The supplied code does not provide any of those functions. Instead, it is a narrow operational hook that post-processes tool activity by checking whether a written text file is valid UTF-8. This is a materially different primary purpose and trigger model: automatic hook execution on file-writing events rather than user-invoked engineering expertise. While encoding validation could be a supportive engineering safeguard, this code chunk is not implementing the declared skill behavior; it is a separate utility/checker with undeclared stdin/file inspection and exit-status behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.