Back to plugin

Security audit

Principles Disciple

Security checks for vulnerabilities and agentic risk

Overview

The plugin’s stated purpose is coherent and mostly disclosed, but it requests startup/hook authority while the published install metadata points to missing runtime bundle files, so it should be reviewed before installation.

Install only if you are comfortable with a plugin that can observe agent conversations/tool activity, store local governance state, and influence future agent behavior through hooks. Because the runtime bundle referenced by the package metadata is missing from this artifact, verify the published package contents and source before trusting it in a real workspace.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documents a rollback/deactivation command that can change live runtime state, but it does not warn the operator that the action may disable an active policy or mitigation and affect ongoing workflows. In an agent-skill context, concise command-oriented instructions can be followed mechanically, so omission of a caution increases the chance of unintended disruptive or security-relevant state changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire skill content are written exclusively in Chinese, including user-facing prompts and instructions, with no indication that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and all operational instructions are written as mandatory Chinese-language behavior, including the final directive to output a structured execution report in Chinese. This creates a locale/language constraint without any user opt-in or documented justification, which is a natural-language policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language instructions and description are written exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata and heading are written in Chinese and the description says the skill is to be used in this form, effectively imposing a specific language/locale. The file does not indicate any user opt-in or alternative language option, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.