Back to skill

Security audit

lexiang-website-sync

Security checks for vulnerabilities and agentic risk

Overview

This is a small documentation-only skill for syncing MedXpert website content, with broad trigger wording but no hidden code or automatic privileged behavior.

Before installing, confirm that you only want this skill to activate for MedXpert/乐享 website synchronization tasks. If used in an agent that auto-selects skills aggressively, narrow the trigger phrases or require confirmation before regenerating local website files.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises activation on very generic keywords like "lexiang", "website", and especially "sync", while also claiming broad multilingual handling. This can cause unintended invocation during ordinary conversations about websites or synchronization tasks, increasing the chance that the agent executes content-sync workflows in the wrong context or against the wrong target.

Static analysis

No suspicious patterns detected.