Back to skill

Security audit

莊子 AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Zhuangzi dialogue and JSON aid with optional evaluation tooling that is aligned with its stated purpose.

Before using dynamic evaluation, expect candidate responses and test prompts to be sent through the configured OpenAI-compatible API and prefer a virtual environment over privileged package installation. For ordinary dialogue and JSON-generation use, the skill's file access and outputs are proportionate to its purpose.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The skill is presented as a Zhuangzi dialogue and JSON-generation tool, but it also instructs use of evaluation scripts, dynamic judging, report generation, and external model-based assessment. This hidden operational scope can cause users or orchestrators to invoke external APIs, process untrusted response maps, or generate artifacts they did not expect, increasing supply-chain and data-handling risk.

Static analysis

No suspicious patterns detected.