Back to skill

Security audit

forklift-benchmark

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local forklift benchmark that samples bundled test questions, scores user/model answers, and generates reports without hidden network, credential, or persistence behavior.

Install only if you want a local Chinese forklift-operation benchmark. Be aware that running protect.py or extend.py with --remove-plaintext intentionally removes local plaintext dataset JSON files inside the skill copy, while normal sampling, scoring, and visualization operate on user-provided files and local bundled data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (68)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The documented packaging/obfuscation workflow includes optional deletion of plaintext benchmark JSON files, which is a real integrity risk in an automated agent setting if exposed without strict scoping or confirmation. The danger is amplified because the skill description is broad and may cause invocation in contexts where users did not intend repository-modifying or destructive behavior.

Ae1

High
Category
analysis-evasion
Content
,读题、作答、评分全程不需要配置任何外部模型 API。代码打包在 `assets/benchmark/`(纯标准库,零第三方运行时依赖),数据集已加密打包进 `assets/benchmark/data.bin`。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
,读题、作答、评分全程不需要配置任何外部模型 API。代码打包在 `assets/benchmark/`(纯标准库,零第三方运行时依赖),数据集已加密打包进 `assets/benchmark/data.bin`。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
,读题、作答、评分全程不需要配置任何外部模型 API。代码打包在 `assets/benchmark/`(纯标准库,零第三方运行时依赖),数据集已加密打包进 `assets/benchmark/data.bin`。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
,读题、作答、评分全程不需要配置任何外部模型 API。代码打包在 `assets/benchmark/`(纯标准库,零第三方运行时依赖),数据集已加密打包进 `assets/benchmark/data.bin`。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
f"先调距到 {w} mm 再起升。"
        )
        hint = f"att={att};cargo={cargo};from={from_loc};to={to_loc};offset={offset};width={w}"
    return instruction, hint


# MOD-2: 三维空间感知与歧义消除
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
f"先调距到 {w} mm 再起升。"
        )
        hint = f"att={att};cargo={cargo};from={from_loc};to={to_loc};offset={offset};width={w}"
    return instruction, hint


# MOD-2: 三维空间感知与歧义消除
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
f"先调距到 {w} mm 再起升。"
        )
        hint = f"att={att};cargo={cargo};from={from_loc};to={to_loc};offset={offset};width={w}"
    return instruction, hint


# MOD-2: 三维空间感知与歧义消除
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
f"先调距到 {w} mm 再起升。"
        )
        hint = f"att={att};cargo={cargo};from={from_loc};to={to_loc};offset={offset};width={w}"
    return instruction, hint


# MOD-2: 三维空间感知与歧义消除
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
f"先调距到 {w} mm 再起升。"
        )
        hint = f"att={att};cargo={cargo};from={from_loc};to={to_loc};offset={offset};width={w}"
    return instruction, hint


# MOD-2: 三维空间感知与歧义消除
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
f"先调距到 {w} mm 再起升。"
        )
        hint = f"att={att};cargo={cargo};from={from_loc};to={to_loc};offset={offset};width={w}"
    return instruction, hint


# MOD-2: 三维空间感知与歧义消除
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This markdown file is written entirely in Chinese, beginning with the heading at L01, and provides no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The README states that the tool takes '一段中文叉车作业指令', and all examples and operating expectations are Chinese-only. Under SQP-3, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified as region-specific or users are given a choice.

Static analysis

No suspicious patterns detected.