Back to skill

Security audit

瓷砖木地板选购指南

Security checks for vulnerabilities and agentic risk

Overview

This skill does not run code, but it needs review because a flooring guide includes broad renovation advice, unsafe DIY guidance, and leftover promotional contact details.

Review before installing. Treat this as a broad, opinionated Chinese home-renovation corpus rather than a narrow flooring guide, avoid surfacing bundled contact details or purchase prompts, and do not rely on it for structural, electrical, plumbing, waterproofing, balcony, or demolition decisions without qualified local professionals and code checks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
references/ref-390.md:19
Finding
Plaintext Personal Contact Information and Promotional Content in Reference Files## Vulnerability Details **File Locations**: - `references/ref-390.md:19-21` - `references/ref-391.md:14-15` - `references/ref-392.md:24-25` - `references/ref-393.md:11-12` - `references/ref-394.md:14-15` - `references/ref-395.md:15-16` **Vulnerability Type**: Plaintext personal contact information and unintended promotional-content exposure **Risk Level**: Low ### Complete Vulnerable Content The following is an English rendering of the complete affected segment in `references/ref-390.md:19-21`: ```text We have worked with integrity in renovation for ten years, and we continue striving! Public platform account: x Personal WeChat and QQ: 493078178 Quick follow: ``` Equivalent personal-contact and follow-account footers are present in the other listed files. ### Technical Analysis The reference corpus retains a personal WeChat/QQ identifier and promotional calls to follow the content publisher. This contradicts the statement in `SKILL.md:21` that referral advertising was removed. The Skill directs the Agent to locate and use these reference files when answering renovation questions. Although no instruction explicitly requires the Agent to reproduce the footer, reference-grounded summarization could include it, especially when an affected article is quoted or reproduced in detail. This issue is classified as insecure Skill content handling because plaintext personal contact data is bundled without being necessary for the Skill's stated functionality. No credential, authentication secret, executable payload, network request, or automatic data transmission was identified. ### Attack Path 1. A user asks a flooring or tile-related question covered by one of the affected historical references. 2. The Agent loads the relevant reference file as instructed by `SKILL.md`. 3. The personal contact and promotional footer enters the Agent's context together with the legitimate renovation guidance. 4. If the Agent qu ...[truncated 909 chars]
Remediation
## Remediation Suggestions 1. Remove personal contact identifiers, public-account advertisements, calls to follow external accounts, and similar promotional footers from every reference file. 2. Review at least `ref-390.md` through `ref-395.md` and the additional references containing public-account or WeChat calls to action. 3. Add a corpus-sanitization step that detects phone numbers, messaging identifiers, email addresses, QR-code prompts, social-media handles, and promotional footer phrases before packaging. 4. Add an explicit instruction to `SKILL.md` prohibiting the reproduction of source contact details, advertisements, external-account promotions, and unrelated attribution metadata. 5. Maintain an allowlist of substantive renovation content and strip recurring publisher boilerplate during ingestion. 6. Add automated tests that fail the build when personal contact data or promotional calls to action are found in reference content. 7. Reconcile the claim that advertising was removed with the packaged corpus, and only retain that claim after automated verification confirms it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file substantially exceeds the skill’s declared scope of tile and wood-floor purchasing guidance and provides broad structural/layout renovation advice, including wall removal and room reconfiguration. In an agent setting, this scope drift is risky because users may rely on the skill for quasi-structural guidance without appropriate safety constraints, disclaimers, or referral to licensed professionals.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The reference content is materially out of scope for a skill advertised as a tile and wood-floor purchasing guide. This creates a data-integrity problem: the agent may retrieve and present irrelevant or misleading advice about avoiding finished homes rather than answering flooring-selection questions, reducing reliability and potentially steering users toward incorrect renovation decisions.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The referenced file is materially out of scope for a skill advertised as a tile and wood-floor purchasing/installation guide, instead focusing on old-house renovation risk and construction caveats. This mismatch can degrade agent behavior by retrieving irrelevant guidance, confusing users, and increasing the chance of inappropriate recommendations in a specialized home-improvement workflow.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The reference shifts from a tile/wood-floor buying guide into general home-product promotion, including lighting, cabinets, and shoe benches. In a skill that users may trust for domain-specific advice, unrelated purchase recommendations can become covert advertising and bias outputs away from the declared purpose.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
These lines contain explicit purchase prompts for unrelated household goods ('click to buy') that are not necessary for providing tile or wood-floor guidance. This creates a risk that the agent will generate unjustified commercial calls-to-action, effectively turning a guidance skill into an undisclosed marketing channel.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The referenced content is materially outside the skill’s declared scope: it provides bedroom wallpaper and décor guidance rather than tile and wood-floor purchasing advice. This creates a scope-integrity issue because an agent may retrieve and present irrelevant guidance to users, reducing reliability and potentially causing incorrect recommendations in a home-renovation context.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The referenced file is materially outside the skill's stated purpose: it focuses on second-hand house renovation and purchase pitfalls rather than tile and wood-floor purchasing guidance. This kind of scope drift is dangerous because it can cause the agent to answer with irrelevant or misleading renovation advice, reducing reliability and potentially influencing costly home decisions based on mismatched content.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file provides whole-home lighting design advice, which is outside the declared scope of a skill dedicated to tile and wood-floor purchasing guidance. This scope drift is dangerous because users and downstream agents may rely on the manifest to determine what the skill is authorized or competent to advise on, leading to misleading outputs, policy bypass, or unintended decision-making beyond the skill’s reviewed domain.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The reference file is materially out of scope for a skill described as a tile and wood-floor purchasing guide: it includes wardrobes, cabinets, sofas, curtains, lighting, appliances, smart home, and general furnishing advice. This broad, mismatched content can cause the agent to answer outside its declared domain, increasing the chance of irrelevant, misleading, or unsafe recommendations and weakening policy boundaries users and integrators rely on.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The reference materially diverges from the skill’s declared scope of tile and wood-floor purchasing guidance and instead provides broad contractor-selection advice. This scope drift can cause the agent to answer outside its intended domain, increasing the risk of irrelevant, misleading, or unsafe recommendations when users expect specialized flooring guidance.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The content includes a direct '24-hour consultation' call-to-action, which can steer users from the skill into an external contact channel without any disclosure, safety notice, or verification context. In a home-renovation purchasing/advice skill, this is not inherently malicious, but it creates a trust and redirection risk because users may interpret it as endorsed by the skill and share personal information off-platform.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document repeatedly recommends destructive renovation steps such as removing insulation, doors, tiles, railings, and even 'extra walls' without any safety caveats about structural limits, waterproofing, fire safety, load, façade rules, or property-management/legal restrictions. In a home-renovation purchasing/advice skill, this can plausibly lead users to undertake unsafe or noncompliant modifications, making the omission materially risky in context.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The content explicitly encourages homeowners to handle demolition and debris removal themselves or hire informal day labor, while framing this as a cost-saving tactic and omitting safety, legal, and disposal-risk warnings. In a home-renovation guidance skill, users may treat this as actionable advice, increasing the chance of injury, structural damage, improper waste handling, or disputes with unlicensed workers.

Missing User Warnings

High
Confidence
97% confidence
Finding
The text advises retaining old plumbing and electrical systems and making only partial modifications based on rough age-based heuristics, without requiring professional inspection, code compliance, load testing, or leak assessment. Because this skill is presented as a renovation buying/selection guide, users could rely on the advice to skip necessary upgrades, creating fire, shock, water-damage, and hidden-defect risks.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The content explicitly normalizes smoking in a home leisure space where children may be present, stating that if there are children at home, smoking would commonly occur there and implying the balcony is a suitable place for it. In a consumer home-improvement skill, this is unsafe because it endorses harmful behavior with secondhand smoke exposure risk, especially to children.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The content gives concrete DIY bathroom repair instructions involving cutting out grout lines and applying sealant, but it does not include any safety cautions, skill-boundary warnings, or limits on when a homeowner should defer to a professional. In a home-improvement skill, this can lead users to perform repairs incorrectly or unsafely, potentially worsening moisture damage, mold issues, or causing minor injury from tools/materials.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The referenced title contains gender-biased and inappropriate comparison language, which is a genuine content-safety issue even though it is not a code-execution or system-compromise vulnerability. In this home-decoration guidance skill, such phrasing can normalize discriminatory or demeaning language, creating reputational, trust, and moderation risk for the product.

Missing User Warnings

High
Confidence
97% confidence
Finding
The content explicitly tells users that a balcony laundry area or through-floor balcony design does not need waterproofing, and repeats that advice as generally applicable. In a home-renovation skill, this can directly lead users to omit a protective measure, increasing the risk of water intrusion, leakage to adjacent rooms or lower floors, mold, and property damage without any warning about code, climate, drainage, or building-specific constraints.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The content gives step-by-step DIY repair instructions involving a knife, cement slurry, and potentially loose tiles, but does not provide clear safety precautions such as wearing gloves/eye protection, isolating the area, or warning about falling wall tiles. In a home-improvement guidance skill, users may treat the instructions as actionable, so omission of basic safety controls increases the risk of cuts, eye exposure, slips, and injury from dislodged tiles.

Static analysis

No suspicious patterns detected.