Back to skill

Security audit

元规 yotta-compliance

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate local compliance-review skill, with disclosed installer cautions around overwriting existing installs and floating npm commands.

Install from a reviewed or pinned version, prefer an explicit --agent or --dir target, and avoid --global unless you really want the skill copied into every supported agent directory. Back up any existing yotta-compliance folder before running install.sh. Treat reports as compliance review aids, not legal advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill performs deterministic compliance review of text/Markdown with built-in legal rule packs and reporting/CI features. The supplied code does none of that. Instead, it is an installation utility that detects directories for various AI agents, creates target folders, and copies package files there. This is a materially different primary purpose and introduces undeclared filesystem deployment behavior. While an installer could be a supporting component of a larger package, the provided code chunk itself does not implement or reflect the described compliance-review functionality, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents the skill as a compliance-review engine for text/Markdown with built-in legal rule packs and reporting capabilities. The provided code chunk does not implement any compliance checking logic, parsing, rule evaluation, report generation, CI gating, or document analysis. Instead, it is an installer script whose primary purpose is deployment: detecting agent skill directories, creating directories, copying files, and removing .git metadata. That is a materially different purpose and includes undeclared filesystem installation behavior. While an installer can be a supporting detail for a larger skill, this chunk by itself does not match the declared operational behavior and instead exposes a separate capability (installation into multiple agent environments).

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The use of rm -rf on a path derived from a caller-controlled install target is dangerous because destructive deletion occurs without validating the resolved destination or ensuring it is a safe, newly created subtree. Although quoting prevents simple shell injection, an attacker or mistaken user can still point installation at an unintended path and cause deletion of repository metadata at that location.

Content

Scanner excerpt · install.sh (reported line 66)May include surrounding context.

sh
install_to() {
  mkdir -p "$1/$SKILL_NAME"
  cp -r "$SOURCE_DIR/." "$1/$SKILL_NAME/"
  rm -rf "$1/$SKILL_NAME/.git"
  echo "installed -> $1/$SKILL_NAME"
}

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to execute npx -y @yottameta/yotta-compliance without pinning an exact package version. This creates a supply-chain risk: future compromised, malicious, or breaking releases from the package or registry could be fetched and executed at install time, especially because npx runs package code directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command again uses npx -y @yottameta/yotta-compliance without an exact version, so users may execute whatever version is current in the registry at the time of installation. In a skill-installation context, that means unreviewed code can be introduced into an agent environment, making the README itself a vector for unsafe operational practice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L001 的语言切换栏将当前文档固定为“中文”,表明该技能文档存在明确的语言定向。按规则,若技能强制特定语言而没有用户选择或 opt-in 说明,属于语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

README 中使用 npx -y @yottameta/yotta-compliance 未固定具体版本,会在安装时拉取最新发布内容。若上游包被恶意更新、账号被劫持或发生供应链投毒,用户执行文档命令时可能安装并运行非预期代码。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

第二处 npx -y @yottameta/yotta-compliance 同样未固定版本,导致安装行为依赖当时 npm registry 上的最新包状态。对技能安装场景而言,这属于典型供应链风险:文档本身会诱导用户直接执行会获取并运行远端代码的命令。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill’s stated purpose is reviewing compliance clauses locally without networking or model calls. Maintaining logic for broad multi-agent deployment targets and writing into their default directories is packaging/deployment functionality rather than a direct requirement of compliance analysis itself.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · bin/install.js (reported line 25)May include surrounding context.

js
const AGENT_DIRS = {
  claude:    { label: 'Claude Code',      dirs: ['.claude/skills'] },
  cursor:    { label: 'Cursor',           dirs: ['.cursor/skills', '.agents/skills'] },
  codex:     { label: 'Codex',            dirs: ['.codex/skills'] }, // 特判:$CODEX_HOME/skills
  gemini:    { label: 'Gemini CLI',       dirs: ['.gemini/skills', '.agents/skills'] },
  goose:     { label: 'Goose',            dirs: ['.config/goose/skills', '.agents/skills'] },
  amp:       { label: 'Amp',              dirs: ['.config/agents/skills', '.agents/skills'] },

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a deterministic, local compliance clause reviewer for text/Markdown that produces reports and CI gating results, emphasizing offline analysis behavior. This installer script instead creates directories and copies the package into agent/project skill folders, which is operational installation behavior not reflected in the skill description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Manifest 将该技能描述为本地离线的合规条款审查器,强调对文本进行规则审查、不联网、不调用模型。该脚本实际执行目录创建、递归复制和删除目标目录下 .git 的安装操作,属于本地环境修改与部署行为,而非合规审查本身。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer writes into user-supplied or auto-detected directories and removes a nested .git directory without any confirmation, dry-run mode, or destructive warning. This can unexpectedly overwrite an existing skill directory or delete repository metadata in a target path, especially if the target already contains content under the same skill name.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install.sh (reported line 124)May include surrounding context.

sh
echo "完成。"; return
  fi
  local installed=0 d
  for d in .claude/skills .cursor/skills .codex/skills .config/goose/skills .config/agents/skills .opencode/skills .codeium/windsurf/skills .workbuddy/skills .kiro/skills .traecli/skills .gemini/skills .trae-cn/skills .qwen/skills .comate/skills .codebuddy/skills .kimi/skills .agents/skills; do
    if [ -d "$d" ]; then install_to "$d"; installed=1; fi
  done
  if [ "$installed" = "0" ]; then

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese and does not indicate that other languages are supported or that Chinese is an optional locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file title and the entire authoring guidance are written in Chinese, and the examples and required wording assume Chinese-language rule authoring. This can constitute a language/locale policy issue because the document effectively forces a specific language without stating that the skill is region-specific or offering an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest sets "jurisdiction": "CN" and defines all trigger lexicon, titles, rationales, and remediation text in Chinese, which effectively constrains the skill to a specific language/locale. Under the policy rule, locale restrictions should either be user-selectable or clearly documented as a justified region-specific tool; this JSON does not include such an explicit justification or opt-in mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest/config file sets "jurisdiction": "CN" and defines rule lexicons entirely in Chinese, which imposes a specific language/locale context. Under the policy, locale constraints should either offer user choice or be clearly documented and justified; this file itself contains no such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

该代码在 review 命令中直接拒绝任何非 zh-CN 的 locale,属于自然语言/区域设置上的强制限制。文件中虽说明 v0.1 仅支持 zh-CN,但这里没有提供用户可选项或充分表明这是仅面向特定区域合规场景的必要限制,符合语言/locale policy violation。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.