Back to skill

Security audit

防偷工减料质量守卫系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly about preventing repeated agent mistakes, but it also tells agents to create lasting rules that can steer future behavior without clear review or limits.

Install only if you want a meta-skill that can shape future agent behavior. Before using it, require explicit approval for MEMORY.md updates, keep rules narrow and provenance-tagged, add an expiry or review process, and avoid turning untrusted user content or one-off mistakes into permanent guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
89% confidence
Finding

The skill explicitly promotes converting each fix into a 'permanent rule' and maintaining a self-evolving memory, which creates a persistent context injection surface. If bad assumptions, attacker-influenced instructions, or overbroad rules are written into long-term memory, future agent behavior can be silently steered across sessions without renewed validation.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Layer 3: Self-Evolving Memory (learning) ├── Error notebook — Every failure documented with 5-Why analysis ├──固化规范 (Hardened Rules) — Each fix becomes a permanent rule └── Pattern library — Error patterns for automatic recognition

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Quick Start section uses broad natural-language trigger phrases like 'Run pre-delivery check' and 'Validate this cron job configuration' without clear activation boundaries, scope limits, or exclusions. In an agent skill system, overly generic invocation text can cause accidental activation in unrelated contexts, leading the agent to apply the skill unexpectedly or to process sensitive content under the wrong workflow.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
94% confidence
Finding

The self-evolution protocol instructs the agent to create a permanent rule in MEMORY.md after an error, which operationalizes persistent context injection into a durable workflow. This is more dangerous in context because the skill is a meta-skill intended to shape future behavior globally, so a poisoned or mistaken rule could propagate widely, suppress safeguards, or bias downstream task handling over time.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
1. **Detect** — Error occurs during execution
2. **Document** — Add to error notebook with 5-Why analysis
3. **Harden** — Create a permanent rule in MEMORY.md
4. **Guard** — Add external skill check if possible
5. **Verify** — Next execution confirms fix works

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The architecture section mixes English with the Chinese phrase "固化规范 (Hardened Rules)" while the document does not state any multilingual policy, user opt-in, or region-specific need. This can conflict with language/locale policy expectations when a skill should not impose language changes without notice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.