Back to skill

Security audit

灯光照明避坑指南

Security checks for vulnerabilities and agentic risk

Overview

The skill has no code or persistence, but it is advertised as a lighting guide while packaging broad renovation, shopping, real-estate, and contractor advice that could be surfaced under the wrong expectation.

Review before installing if you need a narrowly scoped lighting assistant. The main risk is not malware; it is that the skill may answer with broad renovation, purchasing, or demolition advice under a lighting-focused name. Treat electrical, fire, waterproofing, structural, and building-rule advice as informational only and verify with qualified professionals or local requirements.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (26)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file content is materially misaligned with the skill's declared purpose of lighting-specific guidance and instead contains broad DIY and household-reuse hacks. In an agent skill, this kind of scope drift is risky because it can cause the model to surface unsafe, unreviewed advice—especially improvised electrical/flammable lighting ideas such as fabric around bulbs, homemade lamps, and candle-related crafts—under the authority of a lighting expert skill.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
General renovation and reuse advice is not justified for a lighting-specific skill and increases the chance the agent will provide off-domain recommendations without proper safety validation. In this file, several examples involve improvised materials, hot glue, screws, metal sheets, candles, and homemade light fixtures, which can normalize unsafe practices when users expect authoritative lighting guidance.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The reference content is largely unrelated to the skill’s stated purpose of providing focused lighting advice, instead covering general renovation, storage, and promotional material. In an agent skill, this kind of scope drift can mislead downstream responses, degrade trustworthiness, and cause the agent to produce irrelevant or commercially biased recommendations rather than safe, task-aligned guidance.

Context-Inappropriate Capability

Low
Confidence
90% confidence
Finding
The embedded 24-hour renovation consultation / contact-style content introduces lead-generation material into a skill that is supposed to provide neutral lighting guidance. This is risky because an agent may surface or prioritize the promotional call-to-action, steering users off-platform or biasing recommendations toward commercial conversion rather than user benefit.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file content is about whole-home custom cabinetry and interior design comparisons, not lighting guidance as described by the skill metadata. This creates a scope-integrity problem: users relying on the skill for lighting advice may receive irrelevant or misleading material, which can degrade output quality and cause incorrect renovation decisions when the agent retrieves or summarizes the wrong reference.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file content is largely a general home-decoration case study with only incidental mentions of lighting, rather than a focused lighting pitfall-prevention guide as declared by the skill. This creates a scope-integrity problem: an agent using this reference may provide irrelevant or misleading guidance, reducing reliability and increasing the chance of bad renovation decisions based on non-authoritative material.

Context-Inappropriate Capability

Low
Confidence
91% confidence
Finding
The embedded 'click to buy' style product recommendations introduce commercial prompting unrelated or only loosely related to the skill’s stated lighting-guidance purpose. In an agent context, this can bias outputs toward shopping behavior, degrade trust, and create a risk of inappropriate endorsements or covert ad-like recommendations instead of objective safety/quality guidance.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file content is materially unrelated to the declared skill purpose of lighting-design guidance and instead discusses refrigerator placement and room layout. This creates a scope-integrity problem: an agent using this reference may return irrelevant or misleading advice, weakening trust boundaries and making it easier for unrelated or poisoned content to influence outputs.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file content is materially unrelated to the declared skill scope of lighting design and instead contains bathroom waterproofing, drainage slope, plumbing, and electrical renovation guidance. This kind of scope mismatch is dangerous because it can cause the agent to retrieve and present off-domain advice, reducing reliability and potentially leading users to act on incorrect or incomplete guidance in a home-renovation context where mistakes can cause property damage.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file content is clearly about selecting tile brands and pricing, while the skill is declared as a lighting-design and lighting-avoidance guide. This mismatch can cause the agent to retrieve and present irrelevant guidance, reducing trustworthiness and potentially leading users to act on incorrect domain advice when they expected lighting-specific recommendations.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The referenced content is materially misaligned with the skill’s declared purpose of lighting design and lighting-specific guidance. This can cause the agent to retrieve and present irrelevant renovation advice instead of domain-appropriate lighting recommendations, degrading reliability and potentially leading users to make poor decisions based on off-topic content.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is declared as a lighting-design and lighting pitfall guide, but this section contains home-buying advice that is unrelated to lighting. Scope drift is dangerous because it can cause the agent to respond with unsupported or unintended guidance outside its advertised domain, increasing the chance of user harm and trust violations.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
This reference file broadly mixes appliance installation, cabinetry, bathroom, tiling, home-buying, and other renovation advice far beyond lighting. In an agent skill, such overbroad content can override user expectations and cause the model to produce irrelevant or unsafe recommendations in areas where the skill is not intended or described to operate.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The referenced content is materially unrelated to the declared skill purpose. A skill advertised as lighting-design guidance but containing second-hand housing and old-home renovation advice can mislead downstream agents and users, causing incorrect task routing, unsafe recommendations, or trust bypass based on the manifest rather than the actual content. The mismatch is especially risky here because the content includes renovation and safety guidance, so using it in the wrong context could produce harmful home-improvement advice.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file content is about general装修方案诊断 and broader 2025–2026 design trends, while the skill is declared as a dedicated 灯光照明避坑指南. This scope mismatch can cause the agent to retrieve and present irrelevant or weakly related guidance, reducing reliability and potentially leading users to act on non-lighting advice in a lighting-specific workflow.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The referenced content is materially out of scope for a skill advertised as a lighting-design and lighting-selection guide, instead covering HVAC, floor heating, and fresh-air systems. This creates a scope-integrity problem: the agent may retrieve and present irrelevant home-improvement advice, causing user confusion, degraded recommendations, and potentially unsafe sequencing decisions during renovation planning when lighting and MEP systems must be coordinated.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The file content is materially out of scope for a skill advertised as a lighting-design guidance assistant: it focuses on paint, flooring, doors, and ceilings rather than lighting. This creates a scope-integrity problem because users and downstream agents may rely on the manifest description to route queries, but receive unrelated renovation advice, reducing trust and increasing the chance of bad decisions in a home-improvement context.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The referenced content is about ceramic tile selection and purchasing tactics, which does not match the declared skill purpose of lighting design and lighting pitfall guidance. This kind of scope mismatch can cause the agent to retrieve irrelevant advice, reducing reliability and potentially misleading users making home-improvement decisions under the assumption they are receiving lighting-specific guidance.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The file content is materially unrelated to the skill's declared purpose of lighting-design guidance and instead provides flooring and tile selection advice. This kind of scope drift can cause the agent to retrieve and present irrelevant guidance, reducing reliability and potentially leading users to make decisions outside the skill's stated domain without realizing the knowledge base is contaminated.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file content is overwhelmingly about general home furnishing, appliances, curtains, storage, and smart-home advice, while the skill manifest claims it is specifically for lighting-design pitfall avoidance. This scope mismatch can cause the agent to retrieve and present irrelevant guidance as authoritative lighting advice, degrading reliability and potentially causing incorrect renovation decisions in safety-relevant electrical/lighting contexts.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The reference content is about whole-home cabinetry, layout, and storage design, while the skill is declared as a lighting guidance skill. This scope mismatch can cause the agent to answer outside its advertised domain, increasing the chance of misleading users, incorrect recommendations, and policy/control bypass if downstream systems trust the manifest to constrain behavior.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The reference file is substantially out of scope for a lighting-guidance skill and instead provides broad advice on selecting renovation companies and contractors. In an agentic setting, this can cause the skill to answer with irrelevant or misleading procurement guidance, increasing the risk of harmful recommendations, user confusion, and policy drift away from the declared domain.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The file exposes broad reply/click keyword lists without any activation boundaries, making it easier for the skill or surrounding system to match on generic terms unrelated to the user’s lighting intent. In a mis-scoped reference file, these loose triggers increase the chance of unintended retrieval and cross-topic responses.

Vague Triggers

Medium
Confidence
88% confidence
Finding
A second unconstrained keyword block broadens the retrieval surface even further, including many generic home-improvement terms that can collide with legitimate lighting queries. Because this file is already off-topic for the declared skill, these triggers make accidental selection of irrelevant content more likely.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The section recommends removing the balcony sliding door ('拆掉!客厅瞬间显大') as a design improvement but does not include any warning to verify whether the door assembly affects weatherproofing, thermal performance, façade rules, or property-management/building approval requirements. In a home-renovation skill, omission of structural and compliance checks can directly encourage unsafe or non-compliant modifications that may damage the building envelope or create liability for the user.

Static analysis

No suspicious patterns detected.