Back to skill

Security audit

AI 全栈技术面试训练营

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for interview preparation, but it can create GitHub Issues and run external search/scraping workflows from broad triggers without clearly requiring confirmation or a chosen target repository.

Review this carefully before installing if your agent has GitHub write access. Use it only with an intended repository selected, and confirm before letting it create or manage Issues; otherwise treat it as suitable for read-only planning and mock-interview guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes generic terms such as '面试', '技术面试', and '面试准备', which are broad enough to match normal conversation and could activate the skill unintentionally. Because the skill then orchestrates external search/fetch operations and may create GitHub Issues, accidental invocation can lead to unanticipated outbound actions and repository-side changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill workflow normally creates GitHub Issues, but the description and usage flow do not prominently warn users that repository modifications are a standard side effect. This undermines informed consent and increases the chance that a user triggers the skill expecting analysis only, while the agent performs write actions against a connected GitHub repository.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger "准备{公司}{岗位}面试" is broad enough to match ordinary user conversation about interview preparation, which can cause the workflow to activate unintentionally. In a skill that performs external search, scraping, issue creation, and content generation, accidental activation can lead to unintended network actions or repository modifications without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger "制定本周刷题计划" is a generic planning phrase that overlaps with normal assistant usage, so the skill may activate when the user only wants advice rather than workflow execution. Because this entry point chains search, scraping, issue creation, and card rendering, an ambiguous trigger increases the risk of unintended side effects and surprise actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This README presents the skill primarily in Chinese and does not state whether users can opt into another language or locale. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy concern when the skill description gives no alternative.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The trigger "Review 我的{答案}" is less precise than a dedicated command and can collide with normal requests for feedback, particularly in a mixed-language conversation. Although this entry point only invokes the review skill, unintentional activation could still cause the agent to route content into a specialized evaluation workflow the user did not explicitly request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.