Hello Minimax Security Audit
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_33aa5c8b/tencent-document-to-pdf-test.
About this skill
What Problem It Solves
A Skill is often more than documentation. It may include scripts, install commands, remote URLs, and dependency setup. The real risk is not the presence of curl, sudo, or ~/.ssh; it is whether the skill automatically executes those operations and sends sensitive data to untrusted destinations.
This skill treats the audit boundary as supply-chain poisoning risk: it focuses on skill.md plus related docs, scripts, and programs to detect dangerous behavior such as automatic remote script execution, access to cloud credentials or private keys, writes to sensitive system paths, hidden command execution, and mismatches between the stated description and actual behavior.
How It Works and Where It Applies
- Static audit: It reads files, searches keywords, inspects directory structures, and fetches URL text, but it does not execute commands from the skill under review.
- Dangerous behavior detection: It scans for command execution, network requests, privilege escalation, hidden execution, and file operations, then evaluates whether the surrounding context forms a real risk.
- Sensitive path review: It checks paths such as
~/.ssh,.env,~/.aws,~/.kube, andC:\Users, together with read, write, delete, or exfiltration actions. - Remote script deep analysis: When automatic remote execution is found, it retrieves the script text and evaluates second-stage downloads, data exfiltration, persistence, system damage, privilege escalation, and environment tampering.
- Dependency risk checks: It reviews
pip install,npm install -g, non-official indexes, andgit+https://installs, separating environment pollution from supply-chain risk. - Graded reporting: It outputs
P0,P1, orP2conclusions with line numbers, code snippets, risk behaviors, and review recommendations.
Use it with these limits in mind: it does not grade teaching-code quality, so examples with SQL injection or missing error handling are not reported by themselves. If a remote URL is inaccessible or cannot be statically parsed, the result is high risk because safety cannot be verified. Even when a remote script appears benign, the remote execution pattern may still keep the finding at a caution level because content can be swapped or tampered with in transit.
Use Cases
- Run a pre-release security review of a Skill's `skill.md`, scripts, and remote URLs.
- When a skill asks users to execute setup commands, audit whether it auto-downloads and runs remote scripts.
- Check whether bundled scripts read `.env`, cloud credentials, or SSH keys and send them to unknown domains.
- Assess `npm install -g` and non-official package sources for local environment pollution risk.
Best For
- Agent skill maintainers: confirm docs, scripts, and remote execution logic contain no poisoning risk before release.
- Platform security engineers: review whether third-party skills auto-read credentials or run hidden commands.
- DevOps engineers: check whether skill dependency installs pollute the environment or use non-official sources.
- Enterprise AI application owners: assess skill supply-chain security before onboarding internal agents.
Related Skills
Organizes files by extension into subfolders like Documents, Code, and Archives, then outputs a report.
Extract tables, formulas, charts, and layout from invoices, reports, papers, and multi-column documents.
Generates a multi-sheet Excel report containing only structured data tables from byteplan-analysis results.
Automatically sort directory files into type-based folders, with dry-run preview, reports, and JSON custom rules.