Back to skill

Security audit

Code Comment

Security checks for vulnerabilities and agentic risk

Overview

The skill does not run code or access data, but it is scoped so broadly that it can take over many unrelated coding tasks and force Chinese-only full-file output.

Install only if you want a global Chinese comment-style enforcer. Avoid enabling it broadly for code review, explanation, security analysis, multilingual repositories, or projects where comments must preserve existing wording or language.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

该技能把“编写、修改、审查、重构代码”等几乎所有代码相关任务都设为必触发,属于明显的过宽作用域。这样会让一个仅用于注释风格约束的技能在大量不相关场景中介入,覆盖用户原始意图、污染输出格式,甚至干扰更高优先级的安全或功能性指令。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

文件强制要求所有注释和输出使用纯中文,且没有保留用户选择语言或遵循项目既有规范的机制。这会导致对英文代码库、国际化团队、合规文档或必须保留原始术语的场景产生破坏性修改,降低可维护性,并可能错误改写安全相关注释。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.