Back to skill

Security audit

Vue 2 项目 Webpack 升级到 Vite 构建工具

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a Vue 2 to Vite migration workflow, but its optional deployment instructions include plaintext FTP credential use and remote production upload behavior that users should review carefully.

Install only if you are comfortable with a migration assistant that may delete old build files after confirmation. Avoid using the bundled FTP deployment recipe as written; replace it with SFTP/HTTPS/CI deployment, least-privilege credentials, and explicit production approval.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/deploy-config.md:61
Finding

Deployment Credentials and Artifacts Transmitted over Plaintext FTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deploy-config.md (reported line 107)May include surrounding context.

md
# 临时设置(单次部署)
STAGE_FTP_USER=myuser STAGE_FTP_PASSWORD=mypass STAGE_FTP_HOST=ftp.example.com STAGE_FTP_REMOTE_ROOT=/staging/ pnpm run upload:stage

# 或通过 .env.local 文件(需已加入 .gitignore)
# 在 .env.local 中写入:
#   STAGE_FTP_USER=myuser
#   STAGE_FTP_PASSWORD=mypass

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deploy-config.md (reported line 108)May include surrounding context.

md
# 临时设置(单次部署)
STAGE_FTP_USER=myuser STAGE_FTP_PASSWORD=mypass STAGE_FTP_HOST=ftp.example.com STAGE_FTP_REMOTE_ROOT=/staging/ pnpm run upload:stage

# 或通过 .env.local 文件(需已加入 .gitignore)
# 在 .env.local 中写入:
#   STAGE_FTP_USER=myuser
#   STAGE_FTP_PASSWORD=mypass

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The skill includes destructive file-deletion commands (git rm -rf build/ config/) that can modify or remove project files when followed by an agent or user. Although the instructions add some safety checks and use Git to make recovery easier, this is still dangerous in an agent skill because it encourages automated destructive actions based on path assumptions and current working directory state.

Content

Scanner excerpt · references/migration-steps.md (reported line 83)May include surrounding context.

bash
# 删除 Webpack 构建目录
git rm -rf build/ config/
# 删除 Babel/PostCSS 配置
git rm -f .babelrc .postcssrc.js babel.config.js
# 删除旧锁文件(pnpm 项目不需要 npm/yarn 锁文件)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The raw rm -rf build/ config/ instructions are irreversible and can cause substantial data loss if executed in the wrong directory or against a misidentified project. In a skill context, this is more dangerous because agents may operationalize the commands without sufficient environmental validation, turning documentation into an unsafe action recipe.

Content

Scanner excerpt · references/migration-steps.md (reported line 93)May include surrounding context.

如果项目未纳入 Git 版本控制,使用以下命令(不可撤销,执行前务必确认):

bash
rm -rf build/ config/
rm -f .babelrc .postcssrc.js babel.config.js
rm -f package-lock.json yarn.lock

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document title and all instructional content are written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, a skill that implicitly forces a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes this skill as upgrading Vue 2 + Webpack projects to Vite and handling related build/env compatibility issues. The documented scripts add packaging and remote deployment actions (upload:*, deploy:*) that publish build artifacts to an FTP server, which is a separate deployment capability not implied by migration-to-Vite work.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes remote artifact upload and credential-driven deployment logic that is not necessary for a Vite migration task, increasing the attack surface and enabling unintended publication of build artifacts. Although credentials are read from environment variables rather than hardcoded, bundling deployment capability into an upgrade skill can normalize risky execution of remote operations without strong justification or safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file imposes a specific language for all instructions, examples, and warnings, and does not provide any user opt-in, alternative language, or justification that it is intended only for a Chinese-speaking audience. That matches the language/locale policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing operational instructions exclusively in Chinese, including deployment steps and safety guidance. Under the policy rule for language/locale constraints, forcing a single language without user opt-in or justification can be considered a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file is natural-language content, so locale-policy checks apply. The title and all surrounding instructional text are presented only in Chinese, which can imply a fixed language expectation without user opt-in or any documented justification for a Chinese-only scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.