Back to skill

Security audit

ai-fullstack-project-scaffold

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed project scaffolding workflow that generates code and Docker/build files, with normal caution needed because it writes many local project files.

Install only if you want an agent to generate a full project scaffold. Run it in a new or clean directory when possible, review generated source, Makefile, Dockerfile, docker-compose, and configuration before running them, and be cautious using the existing-project mode because conflict or overwrite handling is not clearly documented.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README clearly describes automatic generation of a full project scaffold, including Makefile, Dockerfile, docker-compose, source files, and directories, but it does not explicitly warn that the skill will write many files to disk and may modify the current workspace. In an agent setting, this can lead to unintended filesystem changes, overwriting user work, or unsafe execution in the wrong directory because users may underestimate the write scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very broad (e.g., creating or initializing projects) and overlap with many ordinary development requests, which can cause the skill to activate when the user did not explicitly intend to run a code-generating scaffold. Because this skill can generate files, configs, and deployment artifacts, unintended invocation increases the chance of unwanted file creation, confusing workflow changes, or cascading actions through dependent tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The parameter description states “项目一句话描述(中文即可,AI 自动解析),” which imposes a language expectation in the skill’s instructions. The file does not indicate that other languages are supported, offer an opt-in language choice, or justify the Chinese-only constraint as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly supports running inside an existing project directory to generate missing files, but it does not warn that this may create, modify, or overwrite project files. In context, this is more dangerous because the skill orchestrates multiple code/config generators, so an unintended run in a live repository could alter source, build, or deployment files and introduce destructive or hard-to-review changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list is very broad and matches generic development intents such as creating a project, initializing a project, code generation, and rapid development. This can cause the skill to activate in many ordinary contexts, leading to unintended execution of a multi-step scaffold workflow that invokes several downstream skills and generates files the user may not have explicitly requested.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill description is presented in Chinese, with no indication that users may interact in another language or that the locale is intentionally restricted for a region-specific purpose. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The parameter description says the project description should be provided in Chinese only ("中文即可"), which imposes a language preference without user opt-in. This is a natural-language policy issue because the manifest does not offer alternative languages or explain a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.