Back to skill

Security audit

local-agent-open

Security checks for vulnerabilities and agentic risk

Overview

This is a small local-helper skill that is mainly documentation for opening a localhost assistant page, with disclosed local side effects and no bundled executable code.

Install this only if you expect a skill that helps open a local agent-skeleton page on localhost:3000. Before allowing it to start node server.js or open a preview, confirm the project path and that you are comfortable with a background local server being started; do not allow firewall, hosts, dependency, or public-exposure changes unless you explicitly asked for them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
| 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file begins with a substantive licensing scope notice written primarily in Chinese, while the rest of the license text is in English. This creates a language-policy concern because an important restriction is communicated in a specific language without explicit user opt-in or a documented locale-specific justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description includes very broad trigger phrases and also describes autonomous actions such as probing localhost:3000, starting a local Node.js server, and opening a preview panel. Broad matching increases the chance the skill is invoked in unrelated contexts, which is risky because the described behavior affects local services and browser/UI state without a narrowly scoped user confirmation boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest description is entirely in Chinese and presents the skill behavior and trigger phrases only in that language, with no indication that users may choose another language. This can constitute a language policy issue when the skill does not document user choice or a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.