Security audit
安全卫士
Security checks for vulnerabilities and agentic risk
Overview
The skill presents itself as a local security guardian, but its runtime instructions and included scripts expect broad file read/modify ability (central config single‑source SOP, global search/replace, cache/version writes) while the registry declares no required config paths or credentials; it also contains prompt‑injection test strings and network‑capable imports — the pieces are internally inconsistent and warrant manual review before install.
This skill bundles code and many config files and instructs the agent to read/modify central configuration across the host environment, yet the registry shows no declared permissions — treat that mismatch as risky. Before installing: 1) Verify provenance (author/repository) and confirm the package's origin; 2) Review the full scripts (especially parts truncated here) for any network calls, telemetry, or code paths that POST/GET to external endpoints; 3) If you must test, run inside a strict sandbox with file‑system write disabled (or allow only the skill's own directory) and block outbound network for the process; 4) Do not grant blanket file-write permissions or automatic invocation until you confirm which host config files the skill will modify; 5) Consider asking the author to declare exact required config paths/permissions, or to remove the global search/replace SOP so modifications require explicit, authenticated human approval. If you are not able to audit the full code and confirm there are no external exfiltration paths or unintended file modifications, avoid enabling autonomous invocation or granting write access.
Static analysis
No suspicious patterns detected.
