Back to skill

Security audit

Skill Review Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill reviews other skill files and can optionally help edit them only after user confirmation, with no evidence of hidden network, credential, or persistence behavior.

Install this if you want a Skill reviewer that reads target Skill files and related subdirectories. Before using fix or improve modes, review the proposed diffs because the skill can modify the target Skill after confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill says it does not modify the target Skill, but later defines a workflow that executes fixes. This contradiction weakens operator trust boundaries: a user or supervising system may authorize the skill under a review-only assumption while the prompt still contains instructions for changing artifacts.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 449)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 491)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 492)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 621)May include surrounding context.

md
读取模块时,读取对应 `SKILL.md` 的完整内容作为当前阶段的补充指令。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

格式如下:

text
<!-- FIX_CHECKLIST_START -->
## 修复清单
**目标 Skill**:<skill-name>
**目标文件**:<文件路径>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

格式如下:

text
<!-- FIX_CHECKLIST_START -->
## 修复清单
**目标 Skill**:<skill-name>
**目标文件**:<文件路径>

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as performing static review only, but the body defines additional fix-execution and direct-fix workflows. This capability mismatch can mislead users and higher-level tooling about what the skill may do, reducing informed consent and making unintended modification flows easier to trigger.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to overlap with ordinary conversation such as 'improve skill' or 'benchmark'. In an agent setting, ambiguous activation increases the chance the skill runs in contexts the user did not intend, including reading local files or entering fix-related flows.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
82% confidence
Finding

The skill supports reviewing by installed Skill name and auto-scanning matching directories, which implies local skill enumeration. In a multi-tenant or privacy-sensitive environment, enumeration can disclose what tools are installed and encourage broader file discovery than necessary for a single-task review.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
## 如何指定被测 Skill

1. **文件路径** — "评审 `~/skills/xxx/SKILL.md`" → 直接读取,并自动扫描同目录下的子目录文件
2. **当前对话中的 Skill** — 如果用户刚生成了 Skill,直接评当前生成的
3. **已安装 Skill 名称** — "评审 screenshot-to-prompt" → 在本地 skills 目录查找,并扫描子目录
4. **粘贴内容** — 用户直接贴 Skill 内容 → 只评审贴出的内容(无法扫描子目录)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Direct-fix mode is activated by ambiguous phrases like 'improve' or 'directly fix', which are common in normal discussion. Because this mode can transition from review into repair workflows, ambiguous triggers materially raise the risk of unintended modification behavior.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
82% confidence
Finding

The English section repeats the same enumeration/search behavior, so the risk is present for English-language users as well. Capability to search local skills directories by name can reveal installed assets and widen the file access surface beyond the immediately provided artifact.

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
## How to Specify the Target Skill

1. **File path** — "Review `~/skills/xxx/SKILL.md`" → Read directly, and auto-scan subdirectory files in the same directory
2. **Skill in current conversation** — If user just generated a Skill, review the current one
3. **Installed Skill name** — "Review screenshot-to-prompt" → Search in local skills directory, and scan subdirectories
4. **Pasted content** — User pastes Skill content directly → Review pasted content only (cannot scan subdirectories)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · fix/SKILL.md (reported line 25)May include surrounding context.

md
## 核心原则 / Core Principles

**不主动执行,必须询问用户。** / **Never act without asking.**

每一条修复在执行前,必须:
1. 告诉用户要改什么 / Tell the user what will change

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · fix/SKILL.md (reported line 164)May include surrounding context.

md
## 核心原则 / Core Principles

**不主动执行,必须询问用户。** / **Never act without asking.**

每一条修复在执行前,必须:
1. 告诉用户要改什么 / Tell the user what will change

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · fix/SKILL.md (reported line 154)May include surrounding context.

md
## 约束 / Constraints

- **绝不主动修改** — 每条必须经用户确认 / Never modify without confirmation
- **只修清单里的内容** — 不擅自扩大范围 / Only fix what's in the checklist
- **中英双语同步** — 修中文必须同步修英文 / Keep bilingual in sync
- **不动 frontmatter** — 除非清单明确指出 / Don't touch frontmatter unless specified

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown policy is written primarily in Chinese, with only partial bilingual headings, and the substantive guidance and examples are Chinese-only. That creates a language-policy concern because it effectively requires Chinese comprehension without documenting opt-in, alternatives, or a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document's operative guidance is written in Chinese, which effectively imposes a specific language for understanding and use. There is no indication that users may choose another language or that the Chinese-only requirement is justified by a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document is written as a bilingual Chinese/English policy, but its operative guidance and examples are primarily Chinese-centric and do not indicate that language choice is optional or user-selected. Under the stated rule, natural-language content that imposes a language/locale without opt-in should be flagged unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The adversarial test example is written as a user utterance in Chinese only: “只说'搭个项目'”. This implies a fixed-language interaction pattern and does not provide any opt-in or alternative locale choice, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents the policy primarily in Chinese and does not offer a user language choice or explain that the skill is region-specific. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs scanning subdirectories and reading related files without clearly warning the user that this may involve broad local file access. In agent environments, insufficient disclosure can lead to over-collection of local content beyond what the user expected from a simple review request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.