Back to skill

Security audit

Code Review ProMax

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent code-review skill with disclosed PR/MR fetching and a confirmation-gated fix mode, with no install-time code or persistence.

Install this only if you are comfortable with the agent reading relevant code, diffs, and PR/MR data. For fix mode, review each diff preview before approving; do not provide GitHub or GitLab credentials unless needed for the repository you asked it to review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
---
name: code-review-ProMax
version: "2.0.2"
homepage: https://github.com/z-Zihan/awesome-skills
description: >
  高级代码审查 Agent。对用户提供的 diff、文件、commit、GitHub PR 或 GitLab MR 进行高质量、
  上下文感知、回归风险导向的代码审查,输出可执行、结构化的审查结论,适合合入决策。
  触发词:code review, CR, 代码审查, 审查代码, review代码, review PR/diff/commit,
  review MR, review merge request, review修改, review当前的修改, 帮我review, 帮我看看代码,
  看看有没有问题, 帮我检查一下代码, 代码有没有问题, 这段代码怎么样, 改动有没有风险,
  能不能合入, revie

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list is overly broad and includes common phrases such as '帮我看看代码' and '代码有没有问题', which can match ordinary conversation and invoke the skill unexpectedly. In an agent environment, over-broad activation is dangerous because it can pull the model into special workflows, including repo inspection or downstream sub-skill behavior, without clear user intent.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
88% confidence
Finding

The hidden zero-width character inside the fenced code block marker is an obfuscation technique that can alter rendering or evade straightforward review and policy scanning. Hidden formatting instructions in skill files are suspicious because they can conceal execution-affecting text or make copied content differ from what reviewers visibly inspect.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

修复指令必须用 markdown 代码块(```markdown ... ```)包裹,这样客户端的代码块复制按钮可直接复制全部修复指令。标题保持 ## Code Review 修复任务。

text
​```markdown
## Code Review 修复任务
审查结论: [可直接合入 / 修复后合入 / 建议进一步验证]

Hidden Instructions

High
Category
Prompt Injection
Confidence
88% confidence
Finding

A second hidden character near the closing code fence indicates repeated use of invisible text manipulation rather than an accidental single occurrence. Repeated hidden characters increase the chance of confusing downstream parsers, reviewers, or copy/paste behavior in ways that can mask unsafe instructions.

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

  • 仅修复上述问题,不改动其他代码
  • 保持现有代码风格
  • 修复后确认不影响已有功能 ​```
text

### 直接修复模式

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
**变更来源(按优先级)**:
1. 直接提供 diff/文件内容 → 直接审查
2. Git commit hash → `git show <hash>` 或 `git diff <hash>~1 <hash>`
3. GitHub PR → `gh pr diff <number> -R <owner>/<repo>`;无 gh CLI 则用 GitHub API:`https://api.github.com/repos/{owner}/{repo}/pulls/{number}/files`;需代理时设 `https_proxy`;认证失败(401/403)时提示设 `GITHUB_TOKEN` 或 `gh auth login`
4. GitLab MR → 用 GitLab API:`https://{host}/api/v4/projects/{id}/merge_requests/{number}/changes`;需先 `https://{host}/api/v4/projects?search={project}` 获取 project ID;内网 GitLab(如 gitlab.glm.ai)无需代理,也可用 `git fetch origin merge-requests/<n>/head:mr-<n> && git diff ...mr-<n>`
5. 本地 Git → `git diff` / `git diff --staged` / `git diff HEAD`;`git diff` 返回空时告知用户"当前无改动,是否想审查某个 commit?",不应输出空报告

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is declared as a code-review agent, but the documented '直接修复/fix' mode expands behavior into code modification by delegating to a sub-skill. This creates a scope mismatch that can cause the agent to take write actions when users or operators expect read-only review, increasing the chance of unintended file changes or unsafe automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs direct code modification via a sub-skill when the user says 'fix/修复', but it does not require a warning, dry-run, or confirmation before changing code. That increases the risk of silent or mistaken edits, especially because the parent skill is framed as a reviewer rather than an editor.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The English section repeats a direct-fix capability that exceeds the stated review-only purpose of the skill. Duplicating the behavior in both language sections makes accidental activation more likely and weakens trust boundaries around a supposedly non-mutating review tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition includes very generic terms like "修复" and "fix", which are common in normal conversation and can cause the fix executor to activate without clear user intent. In this skill, unintended activation is risky because the agent is designed to read code context and prepare code changes, increasing the chance of unauthorized or mistaken modification flow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The English trigger logic again relies on the standalone word "fix" plus "etc.", which makes activation scope ambiguous and difficult to reason about safely. Because this skill can move from review context into code-changing behavior, loose triggers raise the likelihood of accidental invocation or prompt-driven misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is written entirely in Chinese and, as described by the finding, does not provide a documented language fallback or user-choice mechanism. While not a classic security flaw, this can create operational safety issues: users may misunderstand prompts, requirements gathering, or review conclusions, leading to incorrect trust in the review outcome and missed defects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The focused-review activation keywords include broad, everyday phrases such as “仔细” and “不放心”, which can appear in normal conversation and accidentally route a request into a specialized review mode. In a code-review skill, unintended activation can cause the agent to apply the wrong workflow, ask for unnecessary requirement artifacts, or produce misleadingly narrow review output that affects merge decisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list is very broad and includes common natural-language review requests such as '帮我看看代码' and '代码有没有问题', which can cause the skill to activate for loosely related conversations rather than only explicit code-review tasks. In an agentic environment, ambiguous invocation scope increases the chance of the wrong skill handling user input, leading to unintended access to code context, misleading outputs, or bypass of more appropriate safety/validation flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The deep-dive trigger keywords like '为什么', '讲讲', and '分析一下' are generic conversational phrases that can match ordinary follow-up questions without confirming they refer to a previously identified review issue. This can cause the skill to enter a more detailed analysis mode in the wrong context, amplifying irrelevant or hallucinated security/code-review output and making agent behavior less predictable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.