Back to skill

Security audit

Evaluation Suite

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local evaluation helper with no evidence of credential access, network exfiltration, persistence, or hidden privileged behavior.

Before installing, be aware that the package metadata appears malformed and the README examples may not run without parameter fixes. From a security perspective, the skill appears low risk: it runs local heuristic evaluation code without external services, secrets, persistence, or privileged system changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
import RAGEvaluator from './src/rag-eval.js';

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
import ReasoningEvaluator from './src/reasoning-eval.js';

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
import HallucinationDetector from './src/hallucination-detector.js';

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown documentation is written entirely in Chinese, including headings, descriptions, and API usage guidance, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, imposing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s primary natural-language description and inline documentation are written in Chinese, including the title '幻觉检测器' and behavior description, with no indication that language is configurable or that users may choose another locale. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JavaScript file contains user-facing natural-language descriptions exclusively in Chinese, including the title, method documentation, and event descriptions. For a general-purpose evaluator, this constitutes a locale/language policy issue because the file enforces a specific language context without offering a user choice or documenting that the skill is intended only for a Chinese-speaking environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file embeds its primary human-readable documentation in Chinese, including the module description and parameter annotations. That creates a language/locale policy issue because the skill does not offer a language choice or explain that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language description in the manifest is written in Chinese only, and the file does not indicate that the skill is intended exclusively for a Chinese-speaking or region-specific audience. Under the policy rule for language or locale constraints, this can be a locale/language restriction without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code file contains natural-language comments naming the evaluator and operations exclusively in Chinese, such as '统一评估入口', '统一评估器', '运行完整评估', '批量评估', and '生成评估报告'. Under the stated policy, forcing a specific language without user choice or justification is a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains multiple natural-language strings exclusively in Chinese, including the file description and test inputs/outputs. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file does not indicate that the Chinese-only behavior is optional or region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.