Back to skill

Security audit

AI Startup MVP Factory

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent MVP automation workflow, but it needs review because it can drive GitHub changes, wiki updates, container builds, registry pushes, and deployable artifacts without clear approval gates or target limits.

Install only if you are comfortable with an agent-assisted workflow that may modify repositories, create PRs, update wiki content, build containers, push images, and produce deployment files. Before use, require explicit confirmation for each external write or publish step, verify target repositories and registries, use least-privilege credentials, and review generated code before any release or deployment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes building images, scanning, pushing to a registry, and generating deployment configuration, but it provides no explicit warning, consent checkpoint, or safety controls for these system-impacting actions. In this context, the workflow can move from untrusted user input to deployable artifacts and publication targets, increasing the risk of unintended release, infrastructure impact, or supply-chain exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README describes an automated chain that generates code, pushes to GitHub, performs PR-based review/sync, and produces container deployment artifacts, but it does not clearly warn users about side effects such as repository writes, network/API calls, CI execution, image publication, or deployment risks. In an agent-skill context, missing disclosure around these actions can cause users to trigger sensitive operations without informed consent, increasing the chance of unintended code exposure, supply-chain changes, or deployment of unsafe generated artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

L003 以及全文说明均以中文定义技能用途与交互预期,但未说明这是可选语言,亦未提供多语言或用户选择机制。根据规则,若技能隐含强制特定语言而没有用户 opt-in,属于自然语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad, everyday phrases such as '从零开始写项目' and '创业项目', which can cause unintended activation in normal conversations. In a skill that orchestrates code generation, PR creation, Wiki sync, and deployment steps, accidental activation can lead to downstream high-impact actions being initiated without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes actions that can modify external systems and produce release artifacts, including creating PRs, syncing Wiki content, pushing container images, and generating deployment files, but does not clearly warn the user or require explicit approval. In this context, the absence of strong consent and execution boundaries increases the risk of unauthorized repository changes, unintended publication, and supply-chain exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow accepts a very broad free-form 'startup idea' and then chains it into code generation, PR creation, deployment, and registry push steps without documented scope boundaries or approval gates. That makes it easier for unsafe, unexpected, or socially engineered requests to trigger high-impact downstream actions far beyond simple document generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest’s primary user-facing description is Chinese, and the workflow step descriptions and metadata are also Chinese. This imposes a specific language on users without any opt-in, alternative language option, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow automatically creates PRs and synchronizes content to a wiki without warning that it will modify external collaboration systems. Because these actions are driven by generated code and documents, they can cause unauthorized changes, spam, sensitive data propagation, or misleading documentation updates if invoked in the wrong repository or workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language instructions and usage guidance are presented in Chinese throughout the README, but the file does not mention that the skill is Chinese-language only or offer an alternative language option. Under the policy, forcing a specific language without user opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.