Back to skill

Security audit

Website Pickpocket

Security checks for vulnerabilities and agentic risk

Overview

The skill is a website-copying guide whose main behavior is disclosed, but it asks users to place active session data in configuration and gives anti-crawling bypass advice without adequate safety boundaries.

Review carefully before installing. Use this only for sites you own or are authorized to copy, keep output in a dedicated directory, set conservative depth and page limits, and avoid putting real cookies or localStorage session values into plaintext configuration unless you are prepared to protect and rotate those credentials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The session section instructs users to supply cookies and localStorage values for authenticated crawling, but it omits any privacy or credential-handling warning. That creates a real risk of exposing active session secrets in config files, logs, shell history, or generated artifacts, potentially allowing account takeover or unauthorized access if those values are mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly promises one-click replication of arbitrary websites and describes downloading HTML, CSS, JS, images, fonts, and media to local storage, but it does not warn users about potentially large disk consumption or mass local writes. This can lead users to unintentionally fill storage, overwrite expected workspace contents, or trigger downstream handling of large untrusted web assets without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The interactive prompt examples are written entirely in Chinese and the skill description does not indicate that language selection is optional or that the tool is intentionally limited to a Chinese-only context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.