Back to skill

Security audit

Local Cpp Code Review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local C/C++ code-review helper that reads user-specified source files and does not include hidden execution, network access, persistence, or privilege changes.

Install this only if you are comfortable with the agent reading C/C++ files in the directory you name. Avoid pointing it at broad repositories or directories containing secrets unless you intend those files to be included in the review context.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to scan local directories and collect code snippets, but it does not warn about access to local files or the possibility of exposing proprietary or sensitive source code in downstream analysis. In an agent setting, this can lead to unintentional disclosure of internal code, secrets embedded in source trees, or other sensitive filesystem contents if users do not understand the data-handling implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Natural-language policy violations include forcing a specific language or locale without user opt-in. This file presents all operating instructions and output expectations in Chinese and does not indicate that users may choose another language or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This file presents all user-facing instructions and trigger phrases exclusively in Chinese, with no indication that users may interact in other languages or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

L54 以“禁止:”开头,但后面的内容是“忽略本地路径中的第三方库……只聚焦于业务源码”。这会把“禁止忽略第三方库”和“应忽略第三方库”两种相反含义混在一起,构成文档层面的主动矛盾,容易误导执行该 skill 的代理行为范围。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a markdown skill description, so it should disclose behaviors that may affect user data or privacy. The file states it will traverse and analyze all .c/.cpp/.h/.hpp files under {TARGET_DIRECTORY}, but provides no warning that local proprietary or sensitive code will be read and processed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.