Back to skill

Security audit

File Organizer Zh 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This Chinese file-organizer skill does what it says, but it can immediately move many local files based on broad trigger words without a preview, confirmation, or undo path.

Install only if you are comfortable with a skill that can reorganize files in Desktop, Downloads, Documents, or a supplied Windows path as soon as it is invoked. Use it first on a small test folder, and avoid broad requests unless the agent confirms the exact target and planned moves before execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill performs destructive file-system changes immediately after inferring a target directory from a natural-language message, without an explicit confirmation step or dry-run preview. In an agent setting, ambiguous phrasing, prompt injection through surrounding context, or simple user misunderstanding could cause large-scale unintended file moves in Desktop, Downloads, or an arbitrary parsed path, disrupting workflows and effectively causing denial of access to expected file locations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic classification and duplicate cleanup but does not warn users that these actions may move, overwrite, or delete files. In this context, the missing warning materially increases the risk of destructive operations being performed without informed consent, leading to data loss or difficult-to-reverse reorganization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are very broad terms like '整理' and '分类', which are common in normal conversation and can cause the skill to activate unintentionally. In a file-management skill, accidental invocation is dangerous because it could reorganize files or initiate duplicate cleanup without the user explicitly intending that action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description, activation keywords, and user-facing messages are all Chinese-only, and activation depends on Chinese trigger words such as '整理' and '分类'. This enforces a specific language/locale behavior without user opt-in or an explicit documented regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package name, description, and keywords explicitly mark the skill as Chinese-only (e.g. 'zh', '中文版', '中文'), but the manifest does not state that users can choose another language or that the locale restriction is required for a region-specific purpose. This creates a natural-language policy concern because it appears to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description and tags explicitly label the skill as a Chinese version, but the file does not indicate that users may choose another language or that the locale restriction is required for a justified region-specific purpose. This can conflict with language-choice policy when a skill implicitly enforces one language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest slug file-organizer-zh indicates a Chinese-language or locale-specific variant, but this file provides no natural-language justification or evidence of user opt-in for that locale constraint. Under the policy, forcing a specific language without documented choice can be a locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.