Back to skill

Security audit

算法带教模式 - 一步步引导用户学习算法,而不是直接给答案

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward algorithm tutoring guide that creates learning notes and solution files as part of its disclosed workflow.

Install this only in a workspace where you are comfortable having an algorithm-training directory, progress.md, README files, and TypeScript solution files created or updated. Ask the agent to preview filenames before writing if you want tighter control.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata explicitly states that it will automatically generate documentation and code files after each problem, but it does not require explicit user confirmation before modifying the workspace. This can lead to unintended file creation or overwriting, especially in environments where the assistant has filesystem access and the user may not expect side effects from a tutoring interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow instructs the agent to update progress.md and generate problem documentation and code files as part of the normal teaching flow, again without a visible warning or consent gate. In practice, this creates a risk of unauthorized workspace changes, accidental overwrites, and persistence of possibly incorrect or sensitive content into user files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.