Back to skill

Security audit

蚁小二一键发布

Security checks across malware telemetry and agentic risk

Overview

This is a narrow bootstrap skill for installing and configuring the yxer CLI, with disclosed global install and API-key handling cautions but no hidden or malicious behavior found.

Install only if you trust the external `@yixiaoermail/cli` package, because it is installed globally and can persist configuration. Avoid pasting production API keys into shared terminals or logs; use a safer interactive or secret-store method if yxer supports one.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The markdown includes a command using `yxer config init --api-key <apiKey>`, which involves supplying a sensitive credential. The file does not provide any warning about protecting the API key, avoiding shell history exposure, or ensuring secure storage, so users may disclose secrets unintentionally.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
All natural-language instructions in the README are presented only in Chinese, and the file does not indicate that this is a region-specific skill or provide an opt-in language choice. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.