问专家技能
Skill documentation explicitly mentions bypassing robot detection and operating on authenticated browser sessions, suggesting potential for unauthorized automation and terms-of-service violations.
The skill explicitly lists 'bypass robot detection scenarios' as an applicable use case. This suggests the tool is designed to circumvent anti-bot measures, which could violate terms of service of various platforms.
SKILL.md:58 Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
No obvious high-risk egress or execution signals were found.
The report includes 0 attack-chain steps and 1 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
SKILL.md explicitly lists 'bypass robot detection scenarios' as use cases
Operates on user's already-logged-in browser without explicit user consent mechanism
Only SKILL.md exists - actual execution logic cannot be verified
Uses mouse automation which could enable screenshot harvesting or click fraud
Most important evidence
Bypass robot detection declared as legitimate use case
The skill explicitly lists 'bypass robot detection scenarios' as an applicable use case. This suggests the tool is designed to circumvent anti-bot measures, which could violate terms of service of various platforms.
SKILL.md:58 Skill name misleads about actual functionality
Skill is named '问专家技能' (Ask Expert Skill) but actually automates browser control through Playwriter. The actual behavior (browser automation) is not apparent from the name.
SKILL.md:1 Authenticated session manipulation without explicit consent
The skill operates on a user's already-logged-in Chrome browser. This means it can potentially access any authenticated sessions (email, banking, social media) without explicit per-action user consent.
SKILL.md:1 No implementation files to audit
Only SKILL.md documentation exists. Actual execution code cannot be reviewed for hidden behavior.
SKILL.md:1 Declared capability vs actual capability
SKILL.md - uses bash, python3 subprocess SKILL.md - controls Chrome via Playwriter SKILL.md - screenshot saving Suspicious artifacts and egress
No obvious IOC was extracted.
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md