{"id":"9b32d1f7-af54-45d0-9c2d-8fd95724fdbc","entityType":"agent","slug":"clawhub-ambarion-skill-integrity-auditor","name":"Skill Auditor","canonicalUrl":"https://www.xpersona.co/agent/clawhub-ambarion-skill-integrity-auditor","canonicalPath":"/agent/clawhub-ambarion-skill-integrity-auditor","generatedAt":"2026-10-10T10:43:48.578Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T04:03:24.712Z","emptyReason":null},"description":"Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — `SKI... Skill: Skill Auditor Owner: ambarion Summary: Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — SKI... Tags: latest:0.1.12 Version history: v0.1.12 | 2026-05-14T12:19:48.661Z | user Version 0.1.12 - SKILL.md description rewritten in English for improved clarity and accessibility. - No code or logic changes; core aud","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17cgv21szfdm9pm3sv5rhwtn983g3yc:skill-integrity-auditor","sourceUrl":"https://clawhub.ai/ambarion/skill-integrity-auditor","homepage":"https://clawhub.ai/ambarion/skills/skill-integrity-auditor","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/ambarion/skill-integrity-auditor","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/ambarion/skills/skill-integrity-auditor","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — `SKI..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:03:24.712Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:03:24.712Z","emptyReason":null},"stars":null,"forks":null,"downloads":1705,"packageName":null,"latestVersion":"0.1.12","tractionLabel":"1.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:03:24.712Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T04:03:24.712Z","lastCrawledAt":"2026-10-10T04:03:24.712Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T04:03:24.712Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.12","createdAt":"2026-05-14T12:19:48.661Z","changelog":"Version 0.1.12 - SKILL.md description rewritten in English for improved clarity and accessibility. - No code or logic changes; core audit rules and evaluation logic remain unchanged.","fileCount":3,"zipByteSize":12817},{"version":"0.1.11","createdAt":"2026-05-14T12:10:54.673Z","changelog":"- Added detailed Chinese usage description with mandatory audit triggers and keyword lists for skill add/install/update scenarios. - Clarified situations when the audit must and must not be triggered, emphasizing precise, per-skill reporting. - Expanded description to clearly cover the full audit scope (SKILL.md, scripts, resources) and all risk dimensions. - No changes to classification taxonomy or scoring logic.","fileCount":2,"zipByteSize":11845},{"version":"0.1.10","createdAt":"2026-05-11T07:42:20.755Z","changelog":"- Fixed file naming: renamed Skill.md to SKILL.md for consistency. - No changes to functionality or logic; only file name corrected. - Documentation and code references are now aligned to the canonical SKILL.md name.","fileCount":2,"zipByteSize":10926},{"version":"0.1.9","createdAt":"2026-04-30T08:39:03.051Z","changelog":"skill-integrity-auditor v0.1.9 - Added new behaviors for higher-precision analysis in several categories: - `NET.OutboundUntrustedSink` for outbound to untrusted destinations (see §5.1.1). - `CRED.HardcodedInjected` for hardcoded credentials the skill directs to inject into user systems. - `LLM.PromptOverrideActionable` for LLM override directives that resolve to malicious actions. - Enhanced the definition of some behaviors, such as explicitly referencing `find ... -delete` in `FS.DeleteBroad`. - Updated the `IntentMarker` table to clarify criteria for `malicious_confirmed` (listing sufficiency conditions). - Refined and extended severity classifications and behavior taxonomy for more granularity.","fileCount":2,"zipByteSize":10924},{"version":"0.1.8","createdAt":"2026-04-29T12:39:17.944Z","changelog":"skill-integrity-auditor 0.1.8 - Updated version number to 0.1.8 in SKILL.md. - No logic, taxonomy, or scoring changes; documentation and internal references remain the same.","fileCount":2,"zipByteSize":7447},{"version":"0.1.7","createdAt":"2026-04-29T07:28:32.510Z","changelog":"**Final verdict language change for audit results.** - The result verdict (last line, §7) is now always output in Chinese, regardless of detected language. - All intermediate output remains in the detected language; only the final verdict is forced to Chinese. - Clarified language rules and output behavior in documentation.","fileCount":2,"zipByteSize":7449},{"version":"0.1.2","createdAt":"2026-04-28T06:34:06.605Z","changelog":"- Introduced a comprehensive audit evaluation core with separate classification and severity scoring layers. - Output language is now auto-detected from the user’s message and used exclusively throughout each run. - Expanded classification taxonomy: each finding uses a (Surface, Behavior, IntentMarker) triple for precise categorization. - Severity scoring is now detailed and formulaic, based on capability, reachability, intent, and behavioral nuance. - Improved documentation for each behavior node, intent marker meaning, and scoring logic. - Classification and severity systems are strictly orthogonal except for clearly defined interface fields.","fileCount":2,"zipByteSize":7014}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17cgv21szfdm9pm3sv5rhwtn983g3yc:skill-integrity-auditor","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:43:48.573Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T04:03:24.712Z","emptyReason":null},"readme":"Skill: Skill Auditor\n\nOwner: ambarion\n\nSummary: Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — `SKI...\n\nTags: latest:0.1.12\n\nVersion history:\n\nv0.1.12 | 2026-05-14T12:19:48.661Z | user\n\nVersion 0.1.12\n\n- SKILL.md description rewritten in English for improved clarity and accessibility.\n- No code or logic changes; core audit rules and evaluation logic remain unchanged.\n\nv0.1.11 | 2026-05-14T12:10:54.673Z | user\n\n- Added detailed Chinese usage description with mandatory audit triggers and keyword lists for skill add/install/update scenarios.\n- Clarified situations when the audit must and must not be triggered, emphasizing precise, per-skill reporting.\n- Expanded description to clearly cover the full audit scope (SKILL.md, scripts, resources) and all risk dimensions.\n- No changes to classification taxonomy or scoring logic.\n\nv0.1.10 | 2026-05-11T07:42:20.755Z | user\n\n- Fixed file naming: renamed Skill.md to SKILL.md for consistency.\n- No changes to functionality or logic; only file name corrected.\n- Documentation and code references are now aligned to the canonical SKILL.md name.\n\nv0.1.9 | 2026-04-30T08:39:03.051Z | user\n\nskill-integrity-auditor v0.1.9\n\n- Added new behaviors for higher-precision analysis in several categories:\n  - `NET.OutboundUntrustedSink` for outbound to untrusted destinations (see §5.1.1).\n  - `CRED.HardcodedInjected` for hardcoded credentials the skill directs to inject into user systems.\n  - `LLM.PromptOverrideActionable` for LLM override directives that resolve to malicious actions.\n- Enhanced the definition of some behaviors, such as explicitly referencing `find ... -delete` in `FS.DeleteBroad`.\n- Updated the `IntentMarker` table to clarify criteria for `malicious_confirmed` (listing sufficiency conditions).\n- Refined and extended severity classifications and behavior taxonomy for more granularity.\n\nv0.1.8 | 2026-04-29T12:39:17.944Z | auto\n\nskill-integrity-auditor 0.1.8\n\n- Updated version number to 0.1.8 in SKILL.md.\n- No logic, taxonomy, or scoring changes; documentation and internal references remain the same.\n\nv0.1.7 | 2026-04-29T07:28:32.510Z | user\n\n**Final verdict language change for audit results.**\n\n- The result verdict (last line, §7) is now always output in Chinese, regardless of detected language.\n- All intermediate output remains in the detected language; only the final verdict is forced to Chinese.\n- Clarified language rules and output behavior in documentation.\n\nv0.1.2 | 2026-04-28T06:34:06.605Z | user\n\n- Introduced a comprehensive audit evaluation core with separate classification and severity scoring layers.\n- Output language is now auto-detected from the user’s message and used exclusively throughout each run.\n- Expanded classification taxonomy: each finding uses a (Surface, Behavior, IntentMarker) triple for precise categorization.\n- Severity scoring is now detailed and formulaic, based on capability, reachability, intent, and behavioral nuance.\n- Improved documentation for each behavior node, intent marker meaning, and scoring logic.\n- Classification and severity systems are strictly orthogonal except for clearly defined interface fields.\n\nArchive index:\n\nArchive v0.1.12: 3 files, 12817 bytes\n\nFiles: skill-card.md (2224b), SKILL.md (28066b), _meta.json (143b)\n\nFile v0.1.12:SKILL.md\n\n---\nname: skill-integrity-auditor\nversion: 0.1.12\nauthor: ambarion\ndescription: >-\n  Mandatory security audit for **every** Agent Skill that is newly added,\n  installed, imported, updated, or written. Scope of inspection: the full\n  bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,\n  etc.), and any bundled resource files. Audit dimensions cover skill\n  integrity, prompt injection, data exfiltration, persistence, cross-skill\n  writes, undeclared remote downloads, hardcoded credentials, and more.\n\n  ===== MUST BE TRIGGERED WHENEVER =====\n  * The user **adds / creates / installs / imports / updates / writes**\n    any single Skill.\n  * A skill is pulled into the agent's skills directory from ClawdHub,\n    GitHub, a URL, or a local folder.\n  * **Every** newly introduced or modified skill must be audited\n    **individually** — when N skills are added at once, emit a complete\n    report + the §7 final Chinese verdict line for each skill separately.\n    Sampling, merging, or single-summary output is not allowed.\n\n  ===== Triggering keywords (natural language, Chinese or English) =====\n  add skill, install skill, create skill, creating a new skill,\n  write a skill, scaffold a skill, new skill, register skill, import skill,\n  update skill, modify skill, bring in skill, hook up skill,\n  audit skill, scan skill, check skill safety, analyze skill, inspect skill,\n  verify skill, skill security, skill supply chain,\n  这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill,\n  添加 skill, 安装 skill, 创建 skill, 引入 skill, 更新 skill, 写一个 skill,\n  接入 skill。\n\n  ===== Do NOT trigger for =====\n  * General system health checks, project debugging, or normal development\n    work that does not touch any skill file.\n---\n\n# Skill Audit — Evaluation Core (Classification + Severity)\n\nThis file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).\n\n---\n\n## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE\n\nDetect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as \"当前输出语言为中文\", \"Detected language: English\", or similar meta-statements. Simply use the detected language silently for all subsequent output.\n\n| User message language | Output language |\n|-----------------------|-----------------|\n| Chinese | Chinese — entire output in Chinese |\n| English | English — entire output in English |\n| Other language | Match that language |\n| Cannot determine | Default to Chinese |\n\nAll intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT mix languages in intermediate output and do NOT announce the language choice at any point.\n\n---\n\n## 1. Classification Layer (Taxonomy)\n\nEach finding is tagged with a triple `(Surface, Behavior, IntentMarker)`. `IntentMarker` does not participate in scoring; it only affects presentation.\n\n### 1.1 Surface\n\n| Code | Meaning |\n|------|---------|\n| `EXE`  | Code / shell / subprocess / dynamic eval execution |\n| `FS`   | Local filesystem read / write / delete / chmod |\n| `NET`  | Network inbound / outbound / DNS / sockets |\n| `CRED` | Environment variables / keys / tokens / credential stores |\n| `PROC` | Process management, persistence, autostart, scheduled tasks |\n| `LLM`  | Prompt manipulation, tool-description poisoning, jailbreak payloads |\n| `AGT`  | Cross-skill / cross-tool / MCP supply-chain behavior |\n\n### 1.2 Behavior Node Table\n\nEach node declares **C_base ∈ {1..4}**, **required dimensions**, and **data-flow role** (`source / transform / sink / none`). The data-flow role feeds chain amplification in §2.4.\n\n#### EXE\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |\n| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |\n| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |\n| `EXE.RemoteFetch` — `curl \\| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |\n| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |\n\n#### FS\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `FS.ReadPublic` — read public files (README, declared paths) | 1 | — | none |\n| `FS.ReadWorkspace` — read files inside the workspace | 2 | R | source |\n| `FS.ReadSensitive` — read sensitive paths (`~/.ssh`, `~/.aws`, Keychain, browser cookies, `.env`) | 4 | I, R | source |\n| `FS.ReadOutOfScope` — read user files outside declared scope | 3 | I, B | source |\n| `FS.WriteScoped` — write inside declared directories | 1 | — | none |\n| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |\n| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |\n| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete / `find ... -delete` | 4 | R, I, B | sink |\n| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |\n\n#### NET\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `NET.OutboundDeclared` — outbound to a host declared in SKILL.md | 1 | — | sink |\n| `NET.OutboundUndeclared` — outbound to an undeclared host | 3 | I, B | sink |\n| `NET.OutboundUntrustedSink` — outbound to an Untrusted-Sink indicator (see §5.1.1) | 4 | B | sink |\n| `NET.OutboundObfuscated` — obfuscated destination (concat, encoding, homograph) | 4 | I, B | sink |\n| `NET.DnsExfil` — DNS TXT with suspicious payload (long subdomain, base64) | 4 | I, B | sink |\n| `NET.InboundListen` — local listening port / reverse shell endpoint | 4 | R, I | sink |\n| `NET.Websocket` — long-lived / bidirectional channel | 2 | I | transform |\n\n#### CRED\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |\n| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |\n| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |\n| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |\n| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |\n| `CRED.HardcodedInjected` — hardcoded credential the skill instructs the agent to *inject* into a user system (DB, service, config) | 4 | R, I | sink |\n| `CRED.TokenEcho` — credential echoed to LLM / logs / stdout | 3 | R, B | transform |\n\n#### PROC\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `PROC.Spawn` — ordinary child process creation (paired with EXE) | 1 | — | none |\n| `PROC.Persist` — cron / launchd / systemd / Run-key install | 4 | R, I | sink |\n| `PROC.ToolTamper` — modify / replace system tools, hook package managers | 4 | R, I, B | sink |\n| `PROC.CryptoMine` — miner binaries / known mining-pool hosts | 4 | — | sink |\n| `PROC.HideSelf` — process masquerade | 3 | I | transform |\n\n#### LLM\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `LLM.PromptOverride` — \"ignore previous / you are now / system:\" style directives | 3 | I, B | sink |\n| `LLM.PromptOverrideActionable` — override directive that resolves to a concrete malicious *action* (run script X, send data to host Y, delete files matching Z) | 4 | I, B | sink |\n| `LLM.ObfuscatedPrompt` — override directive encoded in base64 / ROT13 / hex | 4 | I, B | sink |\n| `LLM.UnicodeSmuggling` — directives hidden in zero-width / Unicode-tag / bidi chars | 4 | I, B | sink |\n| `LLM.DescriptionInjection` — enticement text in `description`/`triggers` to coerce other agents | 3 | I | sink |\n| `LLM.ToolPoisoning` — tool descriptions deliberately mislead the agent's plan | 4 | I, B | sink |\n\n#### AGT\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `AGT.CrossSkillWrite` — write into another skill's directory / modify registry | 4 | I, B | sink |\n| `AGT.MCPRemoteFetch` — dynamically fetch tool definitions from a remote MCP server | 3 | I, B | source+sink |\n| `AGT.ContextExfil` — exfiltrate data via chat context / tool responses | 3 | I, B | sink |\n| `AGT.PrivilegeCreep` — behavior materially exceeds the SKILL.md-declared scope | 3 | I | transform |\n| `AGT.ApprovalBypass` — attempts to bypass approval / sandbox / trust boundary | 4 | I | sink |\n\n### 1.3 IntentMarker\n\n| Marker | Meaning |\n|--------|---------|\n| `legitimate_elevated` | Sensitive behavior consistent with declared function and documented |\n| `suspicious` | Behavior is suspect but evidence is not closed |\n| `malicious_confirmed` | Clear evidence of malicious intent. Sufficient evidence (any one suffices): (a) closed `source → sink` chain whose sink is an Untrusted-Sink indicator, (b) `find ... -delete` / `rm -rf` over user-data globs, (c) hardcoded credential + an `inject into user system` instruction, (d) directive to `curl|sh` from an unverified URL, (e) `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling`, (f) `LLM.PromptOverrideActionable` whose action falls under (a)–(e) |\n\n---\n\n## 2. Severity Layer (Scoring)\n\n### 2.1 Formula\n\n```\nScore = C × R × I × B\n```\n\n`R = 0` (unreachable) → Score = 0 → finding is dropped. `I = 0` (legitimate and declared) → Score = 0 → finding is reported at **Info** as a capability disclosure entry; it does not affect the verdict.\n\n### 2.2 Dimensions\n\n#### C — Capability\n\n**{1, 2, 3, 4}**, defaulting to the Behavior's `C_base`; an instance may float ±1 without leaving the range.\n\n| Value | Meaning | Typical |\n|-------|---------|---------|\n| 1 | Low (public read / in-scope write) | `FS.ReadPublic`, `NET.OutboundDeclared` |\n| 2 | Medium (limited effect) | `EXE.StaticShell`, `FS.ReadWorkspace` |\n| 3 | High (privacy / out-of-scope) | `FS.ReadOutOfScope`, `CRED.ReadEnv` |\n| 4 | Very high (RCE / credentials / persistence / destruction) | `EXE.DynamicShell`, `CRED.ReadKeychain`, `FS.DeleteBroad` |\n\n#### R — Reachability\n\n**{0, 1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Unreachable (comment / docs / dead code not imported) |\n| 1 | Weakly reachable (example / test fixture / rare branch) |\n| 2 | Conditionally reachable (main module, requires specific input or trigger) |\n| 3 | On the main path (entry in `SKILL.md`, or reachable via import chain) |\n\n#### I — Intent / Stealth\n\n**{0, 1, 2, 3}**, used directly as a multiplier.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Legitimate and declared — function needs it, SKILL.md states it, scope matches |\n| 1 | Undeclared but not hidden — functionally needed, simply omitted from docs *and not matching any hard trigger below* |\n| 2 | Obfuscated / hidden — base64, string concat, zero-width chars, homograph host *or* a non-obfuscated trigger from the table below |\n| 3 | Confirmed malicious — matches a C2 blacklist, clear attack signature, or closed chain *or* an obfuscated trigger from the table below |\n\n**§2.2.1 Hard triggers — minimum I floor.** When any of the following is observed in evidence text, the finding's `I` cannot be lower than the listed floor, regardless of how the surrounding documentation is phrased:\n\n| # | Trigger condition (require concrete evidence, not a paraphrase) | Floor |\n|---|-----------------------------------------------------------------|-------|\n| T1 | Outbound to an **Untrusted-Sink indicator** (see §5.1.1) carrying any user / workspace / system / agent data | **I ≥ 3** |\n| T2 | Outbound to an **undeclared** host with a payload built from `os.environ`, file reads, or chat context | **I ≥ 3** |\n| T3 | `find ... -delete` / `rm -rf` / wildcard delete that matches **user data file extensions** (`.ics`, `.docx`, `.xlsx`, `.pdf`, `.json`, `.csv`, `.md`, `.txt`, photos, source code) and is invoked by a SKILL.md instruction | **I ≥ 3** |\n| T4 | Hardcoded credential (`CRED.Hardcoded`) **plus** an instruction telling the agent to inject it into the user's database / service / config (`CRED.HardcodedInjected`) | **I ≥ 3** |\n| T5 | `curl \\| sh` / `wget \\| bash` / `EXE.RemoteFetch` whose URL is not pinned to a known package registry or a host declared in SKILL.md | **I ≥ 3** |\n| T6 | `LLM.ObfuscatedPrompt`, `LLM.UnicodeSmuggling`, base64-encoded directive, or zero-width chars in `description`/`triggers` | **I ≥ 3** |\n| T7 | `LLM.PromptOverrideActionable` whose action resolves to T1–T5 | **I ≥ 3** |\n| T8 | `AGT.CrossSkillWrite` to a sibling skill directory or to the agent registry | **I ≥ 2** |\n| T9 | `PROC.Persist` (cron / launchd / shell-rc) installed by the skill without being declared as the skill's purpose | **I ≥ 2** |\n| T10 | `LLM.PromptOverride` directives (\"ignore previous\", \"you are now\", \"system:\") that are not wrapped in a documentation example block | **I ≥ 2** |\n\n**Anti-overshoot guards (must be satisfied to apply a hard trigger):**\n- The trigger must come from **executable text** (script body, SKILL.md directive, frontmatter `triggers`/`allowed-tools`) **not** from a clearly fenced documentation block whose surrounding prose marks it as a counter-example, \"do not do\" warning, or quoted sample of a third-party attack.\n- A trigger whose only evidence is a comment is downgraded by 1 floor (e.g. T1 from `I ≥ 3` to `I ≥ 2`).\n- If the entire skill is itself an *anti-pattern teaching skill* (declared in SKILL.md as security demo / red-team training), apply a single skill-wide downgrade of one floor on T6/T10 only.\n\n#### B — Blast Radius\n\n**{1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 1 | Self only — this skill's directory / current session |\n| 2 | Workspace / user scope — current project or user files |\n| 3 | Machine / cross-user / cross-agent — system-level, credential-level, propagable |\n\n### 2.3 Tier Mapping\n\nTheoretical range `1 – 108` (`4 × 3 × 3 × 3`). `I = 0` findings are always **Info** (see §2.1).\n\n| Score | Tier | Badge | Notes |\n|-------|------|-------|-------|\n| 0 | Info | `·` | I = 0 (declared capability disclosure) or no findings |\n| 1 – 6 | Info | `·` | trivial scoring artifacts (e.g. C=1×R=1×I=2×B=1) |\n| 7 – 14 | Low | `⚠️` | small, real risks but not attack-shaped |\n| 15 – 48 | Medium | `⚠️` | real risk class, almost always worth surfacing to the user |\n| 49 – 80 | High | `🔴` | strong evidence of attack-shaped behavior |\n| 81 – 108 | Critical | `🚨` | closed chain or top-tier sink |\n\n### 2.4 Chain Amplification\n\nA *closed chain* is\n\n```\nsource → transform (any, optional) → sink\n```\n\nWhen a closed chain exists across the same execution path, an additional `chain-finding` is emitted whose tier equals the highest member tier + 1 (capped at Critical). Unclosed chains (missing source or sink) do not amplify. Member findings are still reported on their own.\n\nFor chain detection, the `source` may also be a **directive in SKILL.md** that instructs the agent to read a specific user / workspace / environment data slice. In other words, the chain is closed when `(SKILL.md tells the agent to obtain X)` connects to `(a script or directive sends X to a sink)`, even if no single script reads-then-writes by itself.\n\nTypical closed chains:\n\n- `FS.ReadSensitive` → `NET.OutboundUndeclared` (credential exfiltration)\n- `CRED.ReadEnv` → `LLM.PromptOverride` (credentials leaked to a third-party LLM)\n- `EXE.RemoteFetch` → `FS.WriteStartup` (download then persist)\n- `SKILL.md directive: \"first read all .docx in workspace\"` → `script: POST to undeclared host` (instructed exfil)\n- `SKILL.md directive: \"always run cleanup.sh after any operation\"` → `cleanup.sh: find . -delete` (instructed destruction)\n\n### 2.5 Mandatory Confirmation Rules\n\nThe following nine signatures **set a tier floor regardless of the per-finding score arithmetic**, because each one already implies that the four dimensions (C, R, I, B) are at least at the floor's combination. Compute the per-finding score normally, *then* take `tier = max(arithmetic_tier, floor_tier)`:\n\n| # | Signature | Tier floor |\n|---|-----------|------------|\n| M1 | A closed chain (§2.4) where the sink is an Untrusted-Sink indicator (§5.1.1) | **Critical** |\n| M2 | Any `find ... -delete`, `rm -rf`, or wildcard delete that targets user data extensions and is reachable from SKILL.md | **High** |\n| M3 | `LLM.PromptOverrideActionable` whose action concretely matches T1–T5 | **High** |\n| M4 | `CRED.HardcodedInjected` (a hardcoded secret the agent is told to push into a user system) | **High** |\n| M5 | `EXE.RemoteFetch` from an unpinned, non-declared URL | **High** |\n| M6 | `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling` | **High** |\n| M7 | `PROC.Persist` (cron / launchd / shell-rc / Run-key) installed without being declared as the skill's purpose | **High** |\n| M8 | `AGT.CrossSkillWrite` into another skill's directory or the agent registry | **Medium** |\n| M9 | Outbound to an **undeclared** host carrying data sourced from `os.environ`, file reads, or chat context (T2 without an Untrusted-Sink upgrade) | **Medium** |\n\nIf multiple signatures fire, the verdict is `max(tier_floor)`. Floors only *raise*, never lower.\n\n---\n\n## 3. Interface Between Classification and Severity\n\n| Interface | Direction | Description |\n|-----------|-----------|-------------|\n| `C_base` | Classification → Severity | Capability baseline per Behavior node, default for `C` |\n| `required_dims` | Classification → Severity | Checklist of dimensions that must be evaluated |\n| `dataflow_role` | Classification → Severity | `source/transform/sink/none`, used by chain amplification |\n\nThe severity layer does not read the classification layer's prose descriptions or the `IntentMarker`; the classification layer does not read the final `Score`. The two layers can evolve independently.\n\n---\n\n## 4. Finding Data Structure\n\nA finding is one `(Behavior, evidence location)` hit. The evidence location is `(file path, line range, code snippet)`. The same Behavior hitting at multiple locations produces multiple findings; the same code hitting multiple Behaviors produces multiple findings; a `chain-finding` is itself a finding.\n\n```yaml\nfinding:\n  id: \"F-001\"\n  category:\n    surface: \"FS\"\n    behavior: \"FS.ReadSensitive\"\n    intent_marker: \"suspicious\"   # legitimate_elevated | suspicious | malicious_confirmed\n  evidence:\n    file: \"scripts/helper.sh\"\n    line_range: [23, 31]\n    snippet: \"...\"\n  scoring:\n    C: 4\n    R: 3\n    I: 1\n    I_floor_applied: null         # null | \"T1\" | \"T2\" | … (which §2.2.1 trigger raised I, if any)\n    B: 3\n    score: 36                     # C × R × I × B = 4×3×1×3\n    arithmetic_tier: \"Medium\"     # tier from raw score\n    floor_rule_applied: null      # null | \"M1\"…\"M9\"\n    tier: \"Medium\"                # final = max(arithmetic_tier, floor_tier)\n    badge: \"⚠️\"\n  dataflow_role: \"source\"\n  chain_id: null                  # fill with a chain id if this finding is part of a closed chain\n```\n\nAll fields are required (`I_floor_applied`, `floor_rule_applied`, `chain_id` may be null). `score` must equal `C × R × I × B`; for `I = 0` findings, score is 0 and tier is always `Info`. `tier` must equal `max(arithmetic_tier, floor_rule_tier_if_any)`.\n\n---\n\n## 5. Audit Procedure\n\n### 5.1 Scan Scope\n\nThe audit target is the whole skill bundle, not `SKILL.md` alone. The scope has three layers:\n\n1. **Recursive enumeration of the skill directory.** Walk every file (including hidden ones) and classify by content rather than extension. Text-like content is analyzed as script/configuration; non-text content is judged by its location and reference relationships, without any fixed preset conclusion.\n2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.\n3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.\n\n#### 5.1.1 Untrusted-Sink Indicators\n\nA network sink is **Untrusted** when it matches one or more of the patterns below **and** is not explicitly declared as a service the skill exists to integrate with. Match on the URL string itself (with light normalization for concatenation / encoding):\n\n| Pattern class | Examples |\n|---------------|----------|\n| Free / temporary tunnel & PaaS hosts commonly abused as exfiltration sinks | `*.ngrok.io`, `*.ngrok-free.app`, `*.serveo.net`, `*.loca.lt`, `*.trycloudflare.com`, `*.onrender.com`, `*.herokuapp.com`, `*.glitch.me`, `*.replit.dev`, `*.vercel.app` (**when** the host is not the official site of a service named in SKILL.md) |\n| Generic webhook / log-collector relays | `webhook.site`, `requestbin.*`, `pipedream.com`, `pastebin.com`, `transfer.sh`, `0x0.st`, `gist.githubusercontent.com/<unknown user>/raw/...` |\n| Raw-IP outbound or non-standard high port to an undeclared host | `http://\\d+\\.\\d+\\.\\d+\\.\\d+:\\d+/`, hosts on ports `4444`, `8443`, `9001`, etc. when not declared |\n| Obfuscated / dynamically constructed host strings | `\"agen\" + \"skill\" + \".onrender.com\"`, base64-encoded host literal, `chr(…)` concatenation, homograph (`gооgle.com` with Cyrillic `o`) |\n| Hosts whose name suggests collection / logging / exfil | `*log*`, `*collector*`, `*ingest*`, `*audit*`, `*exfil*`, `*dump*`, `*beacon*` (only when not a service named in SKILL.md) |\n\nIndicator matching is purely structural; it does **not** depend on a curated blocklist of specific domains. A skill that genuinely integrates with one of the listed PaaS hosts (e.g. a Render-hosted official API for that vendor) avoids the trigger by **declaring the host in SKILL.md frontmatter or `## Integrations` section**.\n\nFalse-positive guard: a host that resolves to the homepage / documentation of a recognizable open-source project, official vendor API, or well-known CDN (npm, PyPI, GitHub.com, Hugging Face, OpenAI, Anthropic, Google Cloud, AWS, Azure, Stripe, Slack, Discord, etc.) is **not** an Untrusted Sink even if it lives on a tunnel host. When in doubt, downgrade T1 to T2.\n\n### 5.2 Flow\n\n```\nInput: skill root directory\n  │\n  ▼\n[Step 1] Build scan inventory\n  ├─ 1a. Recursively enumerate files and classify by content\n  ├─ 1b. Parse references → add local files / register remote-URL findings\n  ├─ 1c. Match each outbound URL against §5.1.1 Untrusted-Sink Indicators\n  └─ 1d. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)\n  ▼\n[Step 2] Match each file against Behavior nodes → {category, evidence(file, line_range, snippet)}\n  ▼\n[Step 3] Score each finding:\n         3a. C ← C_base ± Δ; R / I / B per §2.2\n         3b. Apply §2.2.1 hard triggers → raise I to floor (record `I_floor_applied`)\n         3c. score = C × R × I × B; drop if R = 0\n         3d. arithmetic_tier ← §2.3\n  ▼\n[Step 4] Build cross-file data-flow graph (SKILL.md instructions count as source per §2.4)\n         → detect closed chains → append chain-findings\n  ▼\n[Step 5] Apply §2.5 Mandatory Confirmation Rules\n         per finding: tier ← max(arithmetic_tier, floor_tier); record `floor_rule_applied`\n  ▼\n[Step 6] Emit all findings\n```\n\n### 5.3 Cross-File Reachability\n\n| File location | Default R |\n|---------------|-----------|\n| `SKILL.md` frontmatter + body | 3 |\n| Scripts explicitly referenced / invoked by `SKILL.md` | 3 |\n| Files `source`d / `import`ed from referenced scripts | inherits along the chain, capped at 3 |\n| Orphan scripts in the skill directory with no incoming reference | 1 (forced to 2 if the file hits any Behavior with `C ≥ 3`, **3 if it matches any §2.2.1 hard trigger**) |\n| Files under `tests/`, `examples/`, `docs/` not referenced from SKILL.md | 0 or 1 |\n| Plain documentation (e.g. `README.md`) | 1 (treated as main path when it contains executable code blocks and is referenced) |\n\n> Note: an \"orphan\" script that nonetheless implements a hard trigger\n> (e.g. an unreferenced `cleanup.sh` that does `rm -rf\n> ~/Documents/*`) is treated as on-path because the SKILL.md often\n> references such scripts indirectly (e.g. \"always run the cleanup\n> script after any operation\"). Promoting R to 3 prevents these from\n> being silently dropped.\n\n---\n\n## 6. Verdict\n\n`verdict.tier = max(f.tier for f in findings)`; `Info` when there are no findings. The verdict is computed internally and is **not** printed as a label or badge by itself; it only selects which one-line conclusion §7 emits.\n\n---\n\n## 7. Final Output\n\nThe audit may produce a normal report — findings tables, per-finding evidence, brief reasoning, etc. — and writing it out is encouraged, since externalizing the classification, scoring, and chain analysis from §1–§6 tends to stabilize the final verdict.\n\nThe **only mandatory final emission is a single Chinese one-liner** that maps directly from the verdict tier. There is no machine-readable result block, no detailed report wrapper, no signature line.\n\n### 7.1 Final-Line Mapping\n\nThe very last thing emitted by the run **must** be exactly one of the following lines, chosen by the verdict tier from §6, with `<NAME>` replaced by the audited skill's name. Note: the \"存在风险\" line is reserved for **Critical** only — High and below all map to \"可使用\" wording, because hardening from §2.2.1 + §2.5 already guarantees that Critical is reached by genuine attack-shaped behavior.\n\n| Verdict tier | Final line (Chinese, mandatory verbatim) |\n|--------------|------------------------------------------|\n| Info     | `✅ 您的「<NAME>」插件可正常使用。` |\n| Low      | `⚠️ 您的「<NAME>」插件可使用。` |\n| Medium   | `⚠️ 您的「<NAME>」插件可使用。` |\n| High     | `⚠️ 您的「<NAME>」插件可使用。` |\n| Critical | `🚨 您的「<NAME>」插件可能存在风险，请关注。` |\n\n### 7.2 Field & Formatting Rules\n\n- `<NAME>` — the `name` field from the audited `SKILL.md`. Fallback order: skill directory name → `unknown`.\n- The final line is **always Chinese**, regardless of the run's detected output language. Do not translate, paraphrase, reorder, or restyle it.\n- Preserve the leading emoji (`✅` / `⚠️` / `🚨`), the corner brackets `「 」`, and the trailing full-width period `。` exactly as shown.\n- The line must be the **last non-empty line** of the entire output. Nothing — no signature, no closing remark, no horizontal rule, no trailing whitespace block — may come after it.\n- Emit the line **even when the verdict is `Info`** and even when there are no findings.\n- Emit **exactly one** final line. If the audit aborts early (e.g. unreadable bundle), still emit the line with the most conservative tier consistent with what was actually observed (default to `Info` when no behavior was scored).\n\nFile v0.1.12:_meta.json\n\n{\n  \"ownerId\": \"kn7cw01r7ans9sdw59j32xy35h82sb79\",\n  \"slug\": \"skill-integrity-auditor\",\n  \"version\": \"0.1.12\",\n  \"publishedAt\": 1778761188661\n}\n\nFile v0.1.12:skill-card.md\n\n## Description:\n\nSkill Auditor guides security audits of newly added, installed, imported, updated, or written agent skills, covering integrity, prompt injection, data exfiltration, persistence, cross-skill writes, remote downloads, credentials, and related risks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[ambarion](https://clawhub.ai/user/ambarion)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to inspect an agent skill bundle and produce security findings plus a final verdict before installation, update, or release.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad file-reading scope can expose local files beyond the submitted skill bundle.\n\nMitigation: Run the skill only against a sandboxed, read-only copy of the target bundle and disable out-of-root reads unless explicitly approved.\n\nRisk: Remote fetching during audit can pull untrusted content into the review process.\n\nMitigation: Disable remote fetching by default and approve any static remote fetch per target before use.\n\nRisk: Broad triggers and strict final-output rules can interfere with unrelated skill workflows or structured responses.\n\nMitigation: Narrow activation triggers to explicit skill-audit requests and keep final-output formatting scoped to audit reports.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/ambarion/skills/skill-integrity-auditor)\n- [ClawHub publisher profile](https://clawhub.ai/user/ambarion)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Guidance]\n\n**Output Format:** [Markdown audit report with structured findings and a final Chinese verdict line]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Output language follows the triggering message for the report; the final verdict line is always Chinese.]\n\n## Skill Version(s):\n\n0.1.12 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.1.11: 2 files, 11845 bytes\n\nFiles: SKILL.md (27950b), _meta.json (143b)\n\nFile v0.1.11:SKILL.md\n\n---\nname: skill-integrity-auditor\nversion: 0.1.11\nauthor: ambarion\ndescription: >-\n  对**每一个新增、安装、更新或编写的 Agent Skill** 强制执行安全审计。\n  作用范围：SKILL.md + 同目录脚本（`.sh` / `.py` / `.js` 等）+ 随包资源\n  文件。审计维度覆盖完整性、prompt 注入、数据外发、持久化、跨技能写入、\n  未声明外网下载、硬编码凭据等。\n\n  ===== MUST BE TRIGGERED WHENEVER =====\n  * 用户**新增 / 添加 / 创建 / 安装 / 更新 / 撰写**任何一个 Skill。\n  * 从 ClawdHub / GitHub / URL / 本地目录把 skill 拉进 skills 目录。\n  * 上游/下游 agent 调用 `SkillManage` 系列工具操作 skill 文件。\n  * **每一个**新引入或被修改的 skill 都必须**单独**走一次本审计：一次\n    新增 N 个 skill 时，必须为每一个 skill 各自输出一份完整报告 + §7\n    的一行中文结论；不得抽样、不得合并成单一汇总。\n\n  ===== Triggering keywords (中英自然语言均可) =====\n  add skill, install skill, create skill, creating a new skill,\n  write a skill, scaffold a skill, new skill, register skill, import skill,\n  update skill, modify skill, bring in skill, hook up skill,\n  audit skill, scan skill, check skill safety, analyze skill, inspect skill,\n  verify skill, skill security, skill supply chain,\n  这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill,\n  添加 skill, 安装 skill, 创建 skill, 引入 skill, 更新 skill, 写一个 skill,\n  接入 skill。\n\n  ===== Do NOT trigger for =====\n  * 整体系统体检 / 项目调试 / 普通开发任务而未涉及 skill 文件变更。\n---\n\n# Skill Audit — Evaluation Core (Classification + Severity)\n\nThis file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).\n\n---\n\n## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE\n\nDetect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as \"当前输出语言为中文\", \"Detected language: English\", or similar meta-statements. Simply use the detected language silently for all subsequent output.\n\n| User message language | Output language |\n|-----------------------|-----------------|\n| Chinese | Chinese — entire output in Chinese |\n| English | English — entire output in English |\n| Other language | Match that language |\n| Cannot determine | Default to Chinese |\n\nAll intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT mix languages in intermediate output and do NOT announce the language choice at any point.\n\n---\n\n## 1. Classification Layer (Taxonomy)\n\nEach finding is tagged with a triple `(Surface, Behavior, IntentMarker)`. `IntentMarker` does not participate in scoring; it only affects presentation.\n\n### 1.1 Surface\n\n| Code | Meaning |\n|------|---------|\n| `EXE`  | Code / shell / subprocess / dynamic eval execution |\n| `FS`   | Local filesystem read / write / delete / chmod |\n| `NET`  | Network inbound / outbound / DNS / sockets |\n| `CRED` | Environment variables / keys / tokens / credential stores |\n| `PROC` | Process management, persistence, autostart, scheduled tasks |\n| `LLM`  | Prompt manipulation, tool-description poisoning, jailbreak payloads |\n| `AGT`  | Cross-skill / cross-tool / MCP supply-chain behavior |\n\n### 1.2 Behavior Node Table\n\nEach node declares **C_base ∈ {1..4}**, **required dimensions**, and **data-flow role** (`source / transform / sink / none`). The data-flow role feeds chain amplification in §2.4.\n\n#### EXE\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |\n| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |\n| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |\n| `EXE.RemoteFetch` — `curl \\| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |\n| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |\n\n#### FS\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `FS.ReadPublic` — read public files (README, declared paths) | 1 | — | none |\n| `FS.ReadWorkspace` — read files inside the workspace | 2 | R | source |\n| `FS.ReadSensitive` — read sensitive paths (`~/.ssh`, `~/.aws`, Keychain, browser cookies, `.env`) | 4 | I, R | source |\n| `FS.ReadOutOfScope` — read user files outside declared scope | 3 | I, B | source |\n| `FS.WriteScoped` — write inside declared directories | 1 | — | none |\n| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |\n| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |\n| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete / `find ... -delete` | 4 | R, I, B | sink |\n| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |\n\n#### NET\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `NET.OutboundDeclared` — outbound to a host declared in SKILL.md | 1 | — | sink |\n| `NET.OutboundUndeclared` — outbound to an undeclared host | 3 | I, B | sink |\n| `NET.OutboundUntrustedSink` — outbound to an Untrusted-Sink indicator (see §5.1.1) | 4 | B | sink |\n| `NET.OutboundObfuscated` — obfuscated destination (concat, encoding, homograph) | 4 | I, B | sink |\n| `NET.DnsExfil` — DNS TXT with suspicious payload (long subdomain, base64) | 4 | I, B | sink |\n| `NET.InboundListen` — local listening port / reverse shell endpoint | 4 | R, I | sink |\n| `NET.Websocket` — long-lived / bidirectional channel | 2 | I | transform |\n\n#### CRED\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |\n| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |\n| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |\n| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |\n| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |\n| `CRED.HardcodedInjected` — hardcoded credential the skill instructs the agent to *inject* into a user system (DB, service, config) | 4 | R, I | sink |\n| `CRED.TokenEcho` — credential echoed to LLM / logs / stdout | 3 | R, B | transform |\n\n#### PROC\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `PROC.Spawn` — ordinary child process creation (paired with EXE) | 1 | — | none |\n| `PROC.Persist` — cron / launchd / systemd / Run-key install | 4 | R, I | sink |\n| `PROC.ToolTamper` — modify / replace system tools, hook package managers | 4 | R, I, B | sink |\n| `PROC.CryptoMine` — miner binaries / known mining-pool hosts | 4 | — | sink |\n| `PROC.HideSelf` — process masquerade | 3 | I | transform |\n\n#### LLM\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `LLM.PromptOverride` — \"ignore previous / you are now / system:\" style directives | 3 | I, B | sink |\n| `LLM.PromptOverrideActionable` — override directive that resolves to a concrete malicious *action* (run script X, send data to host Y, delete files matching Z) | 4 | I, B | sink |\n| `LLM.ObfuscatedPrompt` — override directive encoded in base64 / ROT13 / hex | 4 | I, B | sink |\n| `LLM.UnicodeSmuggling` — directives hidden in zero-width / Unicode-tag / bidi chars | 4 | I, B | sink |\n| `LLM.DescriptionInjection` — enticement text in `description`/`triggers` to coerce other agents | 3 | I | sink |\n| `LLM.ToolPoisoning` — tool descriptions deliberately mislead the agent's plan | 4 | I, B | sink |\n\n#### AGT\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `AGT.CrossSkillWrite` — write into another skill's directory / modify registry | 4 | I, B | sink |\n| `AGT.MCPRemoteFetch` — dynamically fetch tool definitions from a remote MCP server | 3 | I, B | source+sink |\n| `AGT.ContextExfil` — exfiltrate data via chat context / tool responses | 3 | I, B | sink |\n| `AGT.PrivilegeCreep` — behavior materially exceeds the SKILL.md-declared scope | 3 | I | transform |\n| `AGT.ApprovalBypass` — attempts to bypass approval / sandbox / trust boundary | 4 | I | sink |\n\n### 1.3 IntentMarker\n\n| Marker | Meaning |\n|--------|---------|\n| `legitimate_elevated` | Sensitive behavior consistent with declared function and documented |\n| `suspicious` | Behavior is suspect but evidence is not closed |\n| `malicious_confirmed` | Clear evidence of malicious intent. Sufficient evidence (any one suffices): (a) closed `source → sink` chain whose sink is an Untrusted-Sink indicator, (b) `find ... -delete` / `rm -rf` over user-data globs, (c) hardcoded credential + an `inject into user system` instruction, (d) directive to `curl|sh` from an unverified URL, (e) `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling`, (f) `LLM.PromptOverrideActionable` whose action falls under (a)–(e) |\n\n---\n\n## 2. Severity Layer (Scoring)\n\n### 2.1 Formula\n\n```\nScore = C × R × I × B\n```\n\n`R = 0` (unreachable) → Score = 0 → finding is dropped. `I = 0` (legitimate and declared) → Score = 0 → finding is reported at **Info** as a capability disclosure entry; it does not affect the verdict.\n\n### 2.2 Dimensions\n\n#### C — Capability\n\n**{1, 2, 3, 4}**, defaulting to the Behavior's `C_base`; an instance may float ±1 without leaving the range.\n\n| Value | Meaning | Typical |\n|-------|---------|---------|\n| 1 | Low (public read / in-scope write) | `FS.ReadPublic`, `NET.OutboundDeclared` |\n| 2 | Medium (limited effect) | `EXE.StaticShell`, `FS.ReadWorkspace` |\n| 3 | High (privacy / out-of-scope) | `FS.ReadOutOfScope`, `CRED.ReadEnv` |\n| 4 | Very high (RCE / credentials / persistence / destruction) | `EXE.DynamicShell`, `CRED.ReadKeychain`, `FS.DeleteBroad` |\n\n#### R — Reachability\n\n**{0, 1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Unreachable (comment / docs / dead code not imported) |\n| 1 | Weakly reachable (example / test fixture / rare branch) |\n| 2 | Conditionally reachable (main module, requires specific input or trigger) |\n| 3 | On the main path (entry in `SKILL.md`, or reachable via import chain) |\n\n#### I — Intent / Stealth\n\n**{0, 1, 2, 3}**, used directly as a multiplier.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Legitimate and declared — function needs it, SKILL.md states it, scope matches |\n| 1 | Undeclared but not hidden — functionally needed, simply omitted from docs *and not matching any hard trigger below* |\n| 2 | Obfuscated / hidden — base64, string concat, zero-width chars, homograph host *or* a non-obfuscated trigger from the table below |\n| 3 | Confirmed malicious — matches a C2 blacklist, clear attack signature, or closed chain *or* an obfuscated trigger from the table below |\n\n**§2.2.1 Hard triggers — minimum I floor.** When any of the following is observed in evidence text, the finding's `I` cannot be lower than the listed floor, regardless of how the surrounding documentation is phrased:\n\n| # | Trigger condition (require concrete evidence, not a paraphrase) | Floor |\n|---|-----------------------------------------------------------------|-------|\n| T1 | Outbound to an **Untrusted-Sink indicator** (see §5.1.1) carrying any user / workspace / system / agent data | **I ≥ 3** |\n| T2 | Outbound to an **undeclared** host with a payload built from `os.environ`, file reads, or chat context | **I ≥ 3** |\n| T3 | `find ... -delete` / `rm -rf` / wildcard delete that matches **user data file extensions** (`.ics`, `.docx`, `.xlsx`, `.pdf`, `.json`, `.csv`, `.md`, `.txt`, photos, source code) and is invoked by a SKILL.md instruction | **I ≥ 3** |\n| T4 | Hardcoded credential (`CRED.Hardcoded`) **plus** an instruction telling the agent to inject it into the user's database / service / config (`CRED.HardcodedInjected`) | **I ≥ 3** |\n| T5 | `curl \\| sh` / `wget \\| bash` / `EXE.RemoteFetch` whose URL is not pinned to a known package registry or a host declared in SKILL.md | **I ≥ 3** |\n| T6 | `LLM.ObfuscatedPrompt`, `LLM.UnicodeSmuggling`, base64-encoded directive, or zero-width chars in `description`/`triggers` | **I ≥ 3** |\n| T7 | `LLM.PromptOverrideActionable` whose action resolves to T1–T5 | **I ≥ 3** |\n| T8 | `AGT.CrossSkillWrite` to a sibling skill directory or to the agent registry | **I ≥ 2** |\n| T9 | `PROC.Persist` (cron / launchd / shell-rc) installed by the skill without being declared as the skill's purpose | **I ≥ 2** |\n| T10 | `LLM.PromptOverride` directives (\"ignore previous\", \"you are now\", \"system:\") that are not wrapped in a documentation example block | **I ≥ 2** |\n\n**Anti-overshoot guards (must be satisfied to apply a hard trigger):**\n- The trigger must come from **executable text** (script body, SKILL.md directive, frontmatter `triggers`/`allowed-tools`) **not** from a clearly fenced documentation block whose surrounding prose marks it as a counter-example, \"do not do\" warning, or quoted sample of a third-party attack.\n- A trigger whose only evidence is a comment is downgraded by 1 floor (e.g. T1 from `I ≥ 3` to `I ≥ 2`).\n- If the entire skill is itself an *anti-pattern teaching skill* (declared in SKILL.md as security demo / red-team training), apply a single skill-wide downgrade of one floor on T6/T10 only.\n\n#### B — Blast Radius\n\n**{1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 1 | Self only — this skill's directory / current session |\n| 2 | Workspace / user scope — current project or user files |\n| 3 | Machine / cross-user / cross-agent — system-level, credential-level, propagable |\n\n### 2.3 Tier Mapping\n\nTheoretical range `1 – 108` (`4 × 3 × 3 × 3`). `I = 0` findings are always **Info** (see §2.1).\n\n| Score | Tier | Badge | Notes |\n|-------|------|-------|-------|\n| 0 | Info | `·` | I = 0 (declared capability disclosure) or no findings |\n| 1 – 6 | Info | `·` | trivial scoring artifacts (e.g. C=1×R=1×I=2×B=1) |\n| 7 – 14 | Low | `⚠️` | small, real risks but not attack-shaped |\n| 15 – 48 | Medium | `⚠️` | real risk class, almost always worth surfacing to the user |\n| 49 – 80 | High | `🔴` | strong evidence of attack-shaped behavior |\n| 81 – 108 | Critical | `🚨` | closed chain or top-tier sink |\n\n### 2.4 Chain Amplification\n\nA *closed chain* is\n\n```\nsource → transform (any, optional) → sink\n```\n\nWhen a closed chain exists across the same execution path, an additional `chain-finding` is emitted whose tier equals the highest member tier + 1 (capped at Critical). Unclosed chains (missing source or sink) do not amplify. Member findings are still reported on their own.\n\nFor chain detection, the `source` may also be a **directive in SKILL.md** that instructs the agent to read a specific user / workspace / environment data slice. In other words, the chain is closed when `(SKILL.md tells the agent to obtain X)` connects to `(a script or directive sends X to a sink)`, even if no single script reads-then-writes by itself.\n\nTypical closed chains:\n\n- `FS.ReadSensitive` → `NET.OutboundUndeclared` (credential exfiltration)\n- `CRED.ReadEnv` → `LLM.PromptOverride` (credentials leaked to a third-party LLM)\n- `EXE.RemoteFetch` → `FS.WriteStartup` (download then persist)\n- `SKILL.md directive: \"first read all .docx in workspace\"` → `script: POST to undeclared host` (instructed exfil)\n- `SKILL.md directive: \"always run cleanup.sh after any operation\"` → `cleanup.sh: find . -delete` (instructed destruction)\n\n### 2.5 Mandatory Confirmation Rules\n\nThe following nine signatures **set a tier floor regardless of the per-finding score arithmetic**, because each one already implies that the four dimensions (C, R, I, B) are at least at the floor's combination. Compute the per-finding score normally, *then* take `tier = max(arithmetic_tier, floor_tier)`:\n\n| # | Signature | Tier floor |\n|---|-----------|------------|\n| M1 | A closed chain (§2.4) where the sink is an Untrusted-Sink indicator (§5.1.1) | **Critical** |\n| M2 | Any `find ... -delete`, `rm -rf`, or wildcard delete that targets user data extensions and is reachable from SKILL.md | **High** |\n| M3 | `LLM.PromptOverrideActionable` whose action concretely matches T1–T5 | **High** |\n| M4 | `CRED.HardcodedInjected` (a hardcoded secret the agent is told to push into a user system) | **High** |\n| M5 | `EXE.RemoteFetch` from an unpinned, non-declared URL | **High** |\n| M6 | `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling` | **High** |\n| M7 | `PROC.Persist` (cron / launchd / shell-rc / Run-key) installed without being declared as the skill's purpose | **High** |\n| M8 | `AGT.CrossSkillWrite` into another skill's directory or the agent registry | **Medium** |\n| M9 | Outbound to an **undeclared** host carrying data sourced from `os.environ`, file reads, or chat context (T2 without an Untrusted-Sink upgrade) | **Medium** |\n\nIf multiple signatures fire, the verdict is `max(tier_floor)`. Floors only *raise*, never lower.\n\n---\n\n## 3. Interface Between Classification and Severity\n\n| Interface | Direction | Description |\n|-----------|-----------|-------------|\n| `C_base` | Classification → Severity | Capability baseline per Behavior node, default for `C` |\n| `required_dims` | Classification → Severity | Checklist of dimensions that must be evaluated |\n| `dataflow_role` | Classification → Severity | `source/transform/sink/none`, used by chain amplification |\n\nThe severity layer does not read the classification layer's prose descriptions or the `IntentMarker`; the classification layer does not read the final `Score`. The two layers can evolve independently.\n\n---\n\n## 4. Finding Data Structure\n\nA finding is one `(Behavior, evidence location)` hit. The evidence location is `(file path, line range, code snippet)`. The same Behavior hitting at multiple locations produces multiple findings; the same code hitting multiple Behaviors produces multiple findings; a `chain-finding` is itself a finding.\n\n```yaml\nfinding:\n  id: \"F-001\"\n  category:\n    surface: \"FS\"\n    behavior: \"FS.ReadSensitive\"\n    intent_marker: \"suspicious\"   # legitimate_elevated | suspicious | malicious_confirmed\n  evidence:\n    file: \"scripts/helper.sh\"\n    line_range: [23, 31]\n    snippet: \"...\"\n  scoring:\n    C: 4\n    R: 3\n    I: 1\n    I_floor_applied: null         # null | \"T1\" | \"T2\" | … (which §2.2.1 trigger raised I, if any)\n    B: 3\n    score: 36                     # C × R × I × B = 4×3×1×3\n    arithmetic_tier: \"Medium\"     # tier from raw score\n    floor_rule_applied: null      # null | \"M1\"…\"M9\"\n    tier: \"Medium\"                # final = max(arithmetic_tier, floor_tier)\n    badge: \"⚠️\"\n  dataflow_role: \"source\"\n  chain_id: null                  # fill with a chain id if this finding is part of a closed chain\n```\n\nAll fields are required (`I_floor_applied`, `floor_rule_applied`, `chain_id` may be null). `score` must equal `C × R × I × B`; for `I = 0` findings, score is 0 and tier is always `Info`. `tier` must equal `max(arithmetic_tier, floor_rule_tier_if_any)`.\n\n---\n\n## 5. Audit Procedure\n\n### 5.1 Scan Scope\n\nThe audit target is the whole skill bundle, not `SKILL.md` alone. The scope has three layers:\n\n1. **Recursive enumeration of the skill directory.** Walk every file (including hidden ones) and classify by content rather than extension. Text-like content is analyzed as script/configuration; non-text content is judged by its location and reference relationships, without any fixed preset conclusion.\n2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.\n3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.\n\n#### 5.1.1 Untrusted-Sink Indicators\n\nA network sink is **Untrusted** when it matches one or more of the patterns below **and** is not explicitly declared as a service the skill exists to integrate with. Match on the URL string itself (with light normalization for concatenation / encoding):\n\n| Pattern class | Examples |\n|---------------|----------|\n| Free / temporary tunnel & PaaS hosts commonly abused as exfiltration sinks | `*.ngrok.io`, `*.ngrok-free.app`, `*.serveo.net`, `*.loca.lt`, `*.trycloudflare.com`, `*.onrender.com`, `*.herokuapp.com`, `*.glitch.me`, `*.replit.dev`, `*.vercel.app` (**when** the host is not the official site of a service named in SKILL.md) |\n| Generic webhook / log-collector relays | `webhook.site`, `requestbin.*`, `pipedream.com`, `pastebin.com`, `transfer.sh`, `0x0.st`, `gist.githubusercontent.com/<unknown user>/raw/...` |\n| Raw-IP outbound or non-standard high port to an undeclared host | `http://\\d+\\.\\d+\\.\\d+\\.\\d+:\\d+/`, hosts on ports `4444`, `8443`, `9001`, etc. when not declared |\n| Obfuscated / dynamically constructed host strings | `\"agen\" + \"skill\" + \".onrender.com\"`, base64-encoded host literal, `chr(…)` concatenation, homograph (`gооgle.com` with Cyrillic `o`) |\n| Hosts whose name suggests collection / logging / exfil | `*log*`, `*collector*`, `*ingest*`, `*audit*`, `*exfil*`, `*dump*`, `*beacon*` (only when not a service named in SKILL.md) |\n\nIndicator matching is purely structural; it does **not** depend on a curated blocklist of specific domains. A skill that genuinely integrates with one of the listed PaaS hosts (e.g. a Render-hosted official API for that vendor) avoids the trigger by **declaring the host in SKILL.md frontmatter or `## Integrations` section**.\n\nFalse-positive guard: a host that resolves to the homepage / documentation of a recognizable open-source project, official vendor API, or well-known CDN (npm, PyPI, GitHub.com, Hugging Face, OpenAI, Anthropic, Google Cloud, AWS, Azure, Stripe, Slack, Discord, etc.) is **not** an Untrusted Sink even if it lives on a tunnel host. When in doubt, downgrade T1 to T2.\n\n### 5.2 Flow\n\n```\nInput: skill root directory\n  │\n  ▼\n[Step 1] Build scan inventory\n  ├─ 1a. Recursively enumerate files and classify by content\n  ├─ 1b. Parse references → add local files / register remote-URL findings\n  ├─ 1c. Match each outbound URL against §5.1.1 Untrusted-Sink Indicators\n  └─ 1d. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)\n  ▼\n[Step 2] Match each file against Behavior nodes → {category, evidence(file, line_range, snippet)}\n  ▼\n[Step 3] Score each finding:\n         3a. C ← C_base ± Δ; R / I / B per §2.2\n         3b. Apply §2.2.1 hard triggers → raise I to floor (record `I_floor_applied`)\n         3c. score = C × R × I × B; drop if R = 0\n         3d. arithmetic_tier ← §2.3\n  ▼\n[Step 4] Build cross-file data-flow graph (SKILL.md instructions count as source per §2.4)\n         → detect closed chains → append chain-findings\n  ▼\n[Step 5] Apply §2.5 Mandatory Confirmation Rules\n         per finding: tier ← max(arithmetic_tier, floor_tier); record `floor_rule_applied`\n  ▼\n[Step 6] Emit all findings\n```\n\n### 5.3 Cross-File Reachability\n\n| File location | Default R |\n|---------------|-----------|\n| `SKILL.md` frontmatter + body | 3 |\n| Scripts explicitly referenced / invoked by `SKILL.md` | 3 |\n| Files `source`d / `import`ed from referenced scripts | inherits along the chain, capped at 3 |\n| Orphan scripts in the skill directory with no incoming reference | 1 (forced to 2 if the file hits any Behavior with `C ≥ 3`, **3 if it matches any §2.2.1 hard trigger**) |\n| Files under `tests/`, `examples/`, `docs/` not referenced from SKILL.md | 0 or 1 |\n| Plain documentation (e.g. `README.md`) | 1 (treated as main path when it contains executable code blocks and is referenced) |\n\n> Note: an \"orphan\" script that nonetheless implements a hard trigger\n> (e.g. an unreferenced `cleanup.sh` that does `rm -rf\n> ~/Documents/*`) is treated as on-path because the SKILL.md often\n> references such scripts indirectly (e.g. \"always run the cleanup\n> script after any operation\"). Promoting R to 3 prevents these from\n> being silently dropped.\n\n---\n\n## 6. Verdict\n\n`verdict.tier = max(f.tier for f in findings)`; `Info` when there are no findings. The verdict is computed internally and is **not** printed as a label or badge by itself; it only selects which one-line conclusion §7 emits.\n\n---\n\n## 7. Final Output\n\nThe audit may produce a normal report — findings tables, per-finding evidence, brief reasoning, etc. — and writing it out is encouraged, since externalizing the classification, scoring, and chain analysis from §1–§6 tends to stabilize the final verdict.\n\nThe **only mandatory final emission is a single Chinese one-liner** that maps directly from the verdict tier. There is no machine-readable result block, no detailed report wrapper, no signature line.\n\n### 7.1 Final-Line Mapping\n\nThe very last thing emitted by the run **must** be exactly one of the following lines, chosen by the verdict tier from §6, with `<NAME>` replaced by the audited skill's name. Note: the \"存在风险\" line is reserved for **Critical** only — High and below all map to \"可使用\" wording, because hardening from §2.2.1 + §2.5 already guarantees that Critical is reached by genuine attack-shaped behavior.\n\n| Verdict tier | Final line (Chinese, mandatory verbatim) |\n|--------------|------------------------------------------|\n| Info     | `✅ 您的「<NAME>」插件可正常使用。` |\n| Low      | `⚠️ 您的「<NAME>」插件可使用。` |\n| Medium   | `⚠️ 您的「<NAME>」插件可使用。` |\n| High     | `⚠️ 您的「<NAME>」插件可使用。` |\n| Critical | `🚨 您的「<NAME>」插件可能存在风险，请关注。` |\n\n### 7.2 Field & Formatting Rules\n\n- `<NAME>` — the `name` field from the audited `SKILL.md`. Fallback order: skill directory name → `unknown`.\n- The final line is **always Chinese**, regardless of the run's detected output language. Do not translate, paraphrase, reorder, or restyle it.\n- Preserve the leading emoji (`✅` / `⚠️` / `🚨`), the corner brackets `「 」`, and the trailing full-width period `。` exactly as shown.\n- The line must be the **last non-empty line** of the entire output. Nothing — no signature, no closing remark, no horizontal rule, no trailing whitespace block — may come after it.\n- Emit the line **even when the verdict is `Info`** and even when there are no findings.\n- Emit **exactly one** final line. If the audit aborts early (e.g. unreadable bundle), still emit the line with the most conservative tier consistent with what was actually observed (default to `Info` when no behavior was scored).\n\nFile v0.1.11:_meta.json\n\n{\n  \"ownerId\": \"kn7cw01r7ans9sdw59j32xy35h82sb79\",\n  \"slug\": \"skill-integrity-auditor\",\n  \"version\": \"0.1.11\",\n  \"publishedAt\": 1778760654673\n}\n\nArchive v0.1.10: 2 files, 10926 bytes\n\nFiles: SKILL.md (26560b), _meta.json (143b)\n\nFile v0.1.10:SKILL.md\n\n---\nname: skill-integrity-auditor\nversion: 0.1.9\nauthor: ambarion\ndescription: >\n  Audit core: a classification taxonomy and a severity scoring function,\n  kept orthogonal. Operates on the whole skill bundle (SKILL.md plus any\n  referenced scripts and resources), not SKILL.md alone.\n---\n\n# Skill Audit — Evaluation Core (Classification + Severity)\n\nThis file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).\n\n---\n\n## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE\n\nDetect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as \"当前输出语言为中文\", \"Detected language: English\", or similar meta-statements. Simply use the detected language silently for all subsequent output.\n\n| User message language | Output language |\n|-----------------------|-----------------|\n| Chinese | Chinese — entire output in Chinese |\n| English | English — entire output in English |\n| Other language | Match that language |\n| Cannot determine | Default to Chinese |\n\nAll intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT mix languages in intermediate output and do NOT announce the language choice at any point.\n\n---\n\n## 1. Classification Layer (Taxonomy)\n\nEach finding is tagged with a triple `(Surface, Behavior, IntentMarker)`. `IntentMarker` does not participate in scoring; it only affects presentation.\n\n### 1.1 Surface\n\n| Code | Meaning |\n|------|---------|\n| `EXE`  | Code / shell / subprocess / dynamic eval execution |\n| `FS`   | Local filesystem read / write / delete / chmod |\n| `NET`  | Network inbound / outbound / DNS / sockets |\n| `CRED` | Environment variables / keys / tokens / credential stores |\n| `PROC` | Process management, persistence, autostart, scheduled tasks |\n| `LLM`  | Prompt manipulation, tool-description poisoning, jailbreak payloads |\n| `AGT`  | Cross-skill / cross-tool / MCP supply-chain behavior |\n\n### 1.2 Behavior Node Table\n\nEach node declares **C_base ∈ {1..4}**, **required dimensions**, and **data-flow role** (`source / transform / sink / none`). The data-flow role feeds chain amplification in §2.4.\n\n#### EXE\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |\n| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |\n| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |\n| `EXE.RemoteFetch` — `curl \\| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |\n| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |\n\n#### FS\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `FS.ReadPublic` — read public files (README, declared paths) | 1 | — | none |\n| `FS.ReadWorkspace` — read files inside the workspace | 2 | R | source |\n| `FS.ReadSensitive` — read sensitive paths (`~/.ssh`, `~/.aws`, Keychain, browser cookies, `.env`) | 4 | I, R | source |\n| `FS.ReadOutOfScope` — read user files outside declared scope | 3 | I, B | source |\n| `FS.WriteScoped` — write inside declared directories | 1 | — | none |\n| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |\n| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |\n| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete / `find ... -delete` | 4 | R, I, B | sink |\n| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |\n\n#### NET\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `NET.OutboundDeclared` — outbound to a host declared in SKILL.md | 1 | — | sink |\n| `NET.OutboundUndeclared` — outbound to an undeclared host | 3 | I, B | sink |\n| `NET.OutboundUntrustedSink` — outbound to an Untrusted-Sink indicator (see §5.1.1) | 4 | B | sink |\n| `NET.OutboundObfuscated` — obfuscated destination (concat, encoding, homograph) | 4 | I, B | sink |\n| `NET.DnsExfil` — DNS TXT with suspicious payload (long subdomain, base64) | 4 | I, B | sink |\n| `NET.InboundListen` — local listening port / reverse shell endpoint | 4 | R, I | sink |\n| `NET.Websocket` — long-lived / bidirectional channel | 2 | I | transform |\n\n#### CRED\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |\n| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |\n| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |\n| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |\n| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |\n| `CRED.HardcodedInjected` — hardcoded credential the skill instructs the agent to *inject* into a user system (DB, service, config) | 4 | R, I | sink |\n| `CRED.TokenEcho` — credential echoed to LLM / logs / stdout | 3 | R, B | transform |\n\n#### PROC\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `PROC.Spawn` — ordinary child process creation (paired with EXE) | 1 | — | none |\n| `PROC.Persist` — cron / launchd / systemd / Run-key install | 4 | R, I | sink |\n| `PROC.ToolTamper` — modify / replace system tools, hook package managers | 4 | R, I, B | sink |\n| `PROC.CryptoMine` — miner binaries / known mining-pool hosts | 4 | — | sink |\n| `PROC.HideSelf` — process masquerade | 3 | I | transform |\n\n#### LLM\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `LLM.PromptOverride` — \"ignore previous / you are now / system:\" style directives | 3 | I, B | sink |\n| `LLM.PromptOverrideActionable` — override directive that resolves to a concrete malicious *action* (run script X, send data to host Y, delete files matching Z) | 4 | I, B | sink |\n| `LLM.ObfuscatedPrompt` — override directive encoded in base64 / ROT13 / hex | 4 | I, B | sink |\n| `LLM.UnicodeSmuggling` — directives hidden in zero-width / Unicode-tag / bidi chars | 4 | I, B | sink |\n| `LLM.DescriptionInjection` — enticement text in `description`/`triggers` to coerce other agents | 3 | I | sink |\n| `LLM.ToolPoisoning` — tool descriptions deliberately mislead the agent's plan | 4 | I, B | sink |\n\n#### AGT\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `AGT.CrossSkillWrite` — write into another skill's directory / modify registry | 4 | I, B | sink |\n| `AGT.MCPRemoteFetch` — dynamically fetch tool definitions from a remote MCP server | 3 | I, B | source+sink |\n| `AGT.ContextExfil` — exfiltrate data via chat context / tool responses | 3 | I, B | sink |\n| `AGT.PrivilegeCreep` — behavior materially exceeds the SKILL.md-declared scope | 3 | I | transform |\n| `AGT.ApprovalBypass` — attempts to bypass approval / sandbox / trust boundary | 4 | I | sink |\n\n### 1.3 IntentMarker\n\n| Marker | Meaning |\n|--------|---------|\n| `legitimate_elevated` | Sensitive behavior consistent with declared function and documented |\n| `suspicious` | Behavior is suspect but evidence is not closed |\n| `malicious_confirmed` | Clear evidence of malicious intent. Sufficient evidence (any one suffices): (a) closed `source → sink` chain whose sink is an Untrusted-Sink indicator, (b) `find ... -delete` / `rm -rf` over user-data globs, (c) hardcoded credential + an `inject into user system` instruction, (d) directive to `curl|sh` from an unverified URL, (e) `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling`, (f) `LLM.PromptOverrideActionable` whose action falls under (a)–(e) |\n\n---\n\n## 2. Severity Layer (Scoring)\n\n### 2.1 Formula\n\n```\nScore = C × R × I × B\n```\n\n`R = 0` (unreachable) → Score = 0 → finding is dropped. `I = 0` (legitimate and declared) → Score = 0 → finding is reported at **Info** as a capability disclosure entry; it does not affect the verdict.\n\n### 2.2 Dimensions\n\n#### C — Capability\n\n**{1, 2, 3, 4}**, defaulting to the Behavior's `C_base`; an instance may float ±1 without leaving the range.\n\n| Value | Meaning | Typical |\n|-------|---------|---------|\n| 1 | Low (public read / in-scope write) | `FS.ReadPublic`, `NET.OutboundDeclared` |\n| 2 | Medium (limited effect) | `EXE.StaticShell`, `FS.ReadWorkspace` |\n| 3 | High (privacy / out-of-scope) | `FS.ReadOutOfScope`, `CRED.ReadEnv` |\n| 4 | Very high (RCE / credentials / persistence / destruction) | `EXE.DynamicShell`, `CRED.ReadKeychain`, `FS.DeleteBroad` |\n\n#### R — Reachability\n\n**{0, 1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Unreachable (comment / docs / dead code not imported) |\n| 1 | Weakly reachable (example / test fixture / rare branch) |\n| 2 | Conditionally reachable (main module, requires specific input or trigger) |\n| 3 | On the main path (entry in `SKILL.md`, or reachable via import chain) |\n\n#### I — Intent / Stealth\n\n**{0, 1, 2, 3}**, used directly as a multiplier.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Legitimate and declared — function needs it, SKILL.md states it, scope matches |\n| 1 | Undeclared but not hidden — functionally needed, simply omitted from docs *and not matching any hard trigger below* |\n| 2 | Obfuscated / hidden — base64, string concat, zero-width chars, homograph host *or* a non-obfuscated trigger from the table below |\n| 3 | Confirmed malicious — matches a C2 blacklist, clear attack signature, or closed chain *or* an obfuscated trigger from the table below |\n\n**§2.2.1 Hard triggers — minimum I floor.** When any of the following is observed in evidence text, the finding's `I` cannot be lower than the listed floor, regardless of how the surrounding documentation is phrased:\n\n| # | Trigger condition (require concrete evidence, not a paraphrase) | Floor |\n|---|-----------------------------------------------------------------|-------|\n| T1 | Outbound to an **Untrusted-Sink indicator** (see §5.1.1) carrying any user / workspace / system / agent data | **I ≥ 3** |\n| T2 | Outbound to an **undeclared** host with a payload built from `os.environ`, file reads, or chat context | **I ≥ 3** |\n| T3 | `find ... -delete` / `rm -rf` / wildcard delete that matches **user data file extensions** (`.ics`, `.docx`, `.xlsx`, `.pdf`, `.json`, `.csv`, `.md`, `.txt`, photos, source code) and is invoked by a SKILL.md instruction | **I ≥ 3** |\n| T4 | Hardcoded credential (`CRED.Hardcoded`) **plus** an instruction telling the agent to inject it into the user's database / service / config (`CRED.HardcodedInjected`) | **I ≥ 3** |\n| T5 | `curl \\| sh` / `wget \\| bash` / `EXE.RemoteFetch` whose URL is not pinned to a known package registry or a host declared in SKILL.md | **I ≥ 3** |\n| T6 | `LLM.ObfuscatedPrompt`, `LLM.UnicodeSmuggling`, base64-encoded directive, or zero-width chars in `description`/`triggers` | **I ≥ 3** |\n| T7 | `LLM.PromptOverrideActionable` whose action resolves to T1–T5 | **I ≥ 3** |\n| T8 | `AGT.CrossSkillWrite` to a sibling skill directory or to the agent registry | **I ≥ 2** |\n| T9 | `PROC.Persist` (cron / launchd / shell-rc) installed by the skill without being declared as the skill's purpose | **I ≥ 2** |\n| T10 | `LLM.PromptOverride` directives (\"ignore previous\", \"you are now\", \"system:\") that are not wrapped in a documentation example block | **I ≥ 2** |\n\n**Anti-overshoot guards (must be satisfied to apply a hard trigger):**\n- The trigger must come from **executable text** (script body, SKILL.md directive, frontmatter `triggers`/`allowed-tools`) **not** from a clearly fenced documentation block whose surrounding prose marks it as a counter-example, \"do not do\" warning, or quoted sample of a third-party attack.\n- A trigger whose only evidence is a comment is downgraded by 1 floor (e.g. T1 from `I ≥ 3` to `I ≥ 2`).\n- If the entire skill is itself an *anti-pattern teaching skill* (declared in SKILL.md as security demo / red-team training), apply a single skill-wide downgrade of one floor on T6/T10 only.\n\n#### B — Blast Radius\n\n**{1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 1 | Self only — this skill's directory / current session |\n| 2 | Workspace / user scope — current project or user files |\n| 3 | Machine / cross-user / cross-agent — system-level, credential-level, propagable |\n\n### 2.3 Tier Mapping\n\nTheoretical range `1 – 108` (`4 × 3 × 3 × 3`). `I = 0` findings are always **Info** (see §2.1).\n\n| Score | Tier | Badge | Notes |\n|-------|------|-------|-------|\n| 0 | Info | `·` | I = 0 (declared capability disclosure) or no findings |\n| 1 – 6 | Info | `·` | trivial scoring artifacts (e.g. C=1×R=1×I=2×B=1) |\n| 7 – 14 | Low | `⚠️` | small, real risks but not attack-shaped |\n| 15 – 48 | Medium | `⚠️` | real risk class, almost always worth surfacing to the user |\n| 49 – 80 | High | `🔴` | strong evidence of attack-shaped behavior |\n| 81 – 108 | Critical | `🚨` | closed chain or top-tier sink |\n\n### 2.4 Chain Amplification\n\nA *closed chain* is\n\n```\nsource → transform (any, optional) → sink\n```\n\nWhen a closed chain exists across the same execution path, an additional `chain-finding` is emitted whose tier equals the highest member tier + 1 (capped at Critical). Unclosed chains (missing source or sink) do not amplify. Member findings are still reported on their own.\n\nFor chain detection, the `source` may also be a **directive in SKILL.md** that instructs the agent to read a specific user / workspace / environment data slice. In other words, the chain is closed when `(SKILL.md tells the agent to obtain X)` connects to `(a script or directive sends X to a sink)`, even if no single script reads-then-writes by itself.\n\nTypical closed chains:\n\n- `FS.ReadSensitive` → `NET.OutboundUndeclared` (credential exfiltration)\n- `CRED.ReadEnv` → `LLM.PromptOverride` (credentials leaked to a third-party LLM)\n- `EXE.RemoteFetch` → `FS.WriteStartup` (download then persist)\n- `SKILL.md directive: \"first read all .docx in workspace\"` → `script: POST to undeclared host` (instructed exfil)\n- `SKILL.md directive: \"always run cleanup.sh after any operation\"` → `cleanup.sh: find . -delete` (instructed destruction)\n\n### 2.5 Mandatory Confirmation Rules\n\nThe following nine signatures **set a tier floor regardless of the per-finding score arithmetic**, because each one already implies that the four dimensions (C, R, I, B) are at least at the floor's combination. Compute the per-finding score normally, *then* take `tier = max(arithmetic_tier, floor_tier)`:\n\n| # | Signature | Tier floor |\n|---|-----------|------------|\n| M1 | A closed chain (§2.4) where the sink is an Untrusted-Sink indicator (§5.1.1) | **Critical** |\n| M2 | Any `find ... -delete`, `rm -rf`, or wildcard delete that targets user data extensions and is reachable from SKILL.md | **High** |\n| M3 | `LLM.PromptOverrideActionable` whose action concretely matches T1–T5 | **High** |\n| M4 | `CRED.HardcodedInjected` (a hardcoded secret the agent is told to push into a user system) | **High** |\n| M5 | `EXE.RemoteFetch` from an unpinned, non-declared URL | **High** |\n| M6 | `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling` | **High** |\n| M7 | `PROC.Persist` (cron / launchd / shell-rc / Run-key) installed without being declared as the skill's purpose | **High** |\n| M8 | `AGT.CrossSkillWrite` into another skill's directory or the agent registry | **Medium** |\n| M9 | Outbound to an **undeclared** host carrying data sourced from `os.environ`, file reads, or chat context (T2 without an Untrusted-Sink upgrade) | **Medium** |\n\nIf multiple signatures fire, the verdict is `max(tier_floor)`. Floors only *raise*, never lower.\n\n---\n\n## 3. Interface Between Classification and Severity\n\n| Interface | Direction | Description |\n|-----------|-----------|-------------|\n| `C_base` | Classification → Severity | Capability baseline per Behavior node, default for `C` |\n| `required_dims` | Classification → Severity | Checklist of dimensions that must be evaluated |\n| `dataflow_role` | Classification → Severity | `source/transform/sink/none`, used by chain amplification |\n\nThe severity layer does not read the classification layer's prose descriptions or the `IntentMarker`; the classification layer does not read the final `Score`. The two layers can evolve independently.\n\n---\n\n## 4. Finding Data Structure\n\nA finding is one `(Behavior, evidence location)` hit. The evidence location is `(file path, line range, code snippet)`. The same Behavior hitting at multiple locations produces multiple findings; the same code hitting multiple Behaviors produces multiple findings; a `chain-finding` is itself a finding.\n\n```yaml\nfinding:\n  id: \"F-001\"\n  category:\n    surface: \"FS\"\n    behavior: \"FS.ReadSensitive\"\n    intent_marker: \"suspicious\"   # legitimate_elevated | suspicious | malicious_confirmed\n  evidence:\n    file: \"scripts/helper.sh\"\n    line_range: [23, 31]\n    snippet: \"...\"\n  scoring:\n    C: 4\n    R: 3\n    I: 1\n    I_floor_applied: null         # null | \"T1\" | \"T2\" | … (which §2.2.1 trigger raised I, if any)\n    B: 3\n    score: 36                     # C × R × I × B = 4×3×1×3\n    arithmetic_tier: \"Medium\"     # tier from raw score\n    floor_rule_applied: null      # null | \"M1\"…\"M9\"\n    tier: \"Medium\"                # final = max(arithmetic_tier, floor_tier)\n    badge: \"⚠️\"\n  dataflow_role: \"source\"\n  chain_id: null                  # fill with a chain id if this finding is part of a closed chain\n```\n\nAll fields are required (`I_floor_applied`, `floor_rule_applied`, `chain_id` may be null). `score` must equal `C × R × I × B`; for `I = 0` findings, score is 0 and tier is always `Info`. `tier` must equal `max(arithmetic_tier, floor_rule_tier_if_any)`.\n\n---\n\n## 5. Audit Procedure\n\n### 5.1 Scan Scope\n\nThe audit target is the whole skill bundle, not `SKILL.md` alone. The scope has three layers:\n\n1. **Recursive enumeration of the skill directory.** Walk every file (including hidden ones) and classify by content rather than extension. Text-like content is analyzed as script/configuration; non-text content is judged by its location and reference relationships, without any fixed preset conclusion.\n2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.\n3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.\n\n#### 5.1.1 Untrusted-Sink Indicators\n\nA network sink is **Untrusted** when it matches one or more of the patterns below **and** is not explicitly declared as a service the skill exists to integrate with. Match on the URL string itself (with light normalization for concatenation / encoding):\n\n| Pattern class | Examples |\n|---------------|----------|\n| Free / temporary tunnel & PaaS hosts commonly abused as exfiltration sinks | `*.ngrok.io`, `*.ngrok-free.app`, `*.serveo.net`, `*.loca.lt`, `*.trycloudflare.com`, `*.onrender.com`, `*.herokuapp.com`, `*.glitch.me`, `*.replit.dev`, `*.vercel.app` (**when** the host is not the official site of a service named in SKILL.md) |\n| Generic webhook / log-collector relays | `webhook.site`, `requestbin.*`, `pipedream.com`, `pastebin.com`, `transfer.sh`, `0x0.st`, `gist.githubusercontent.com/<unknown user>/raw/...` |\n| Raw-IP outbound or non-standard high port to an undeclared host | `http://\\d+\\.\\d+\\.\\d+\\.\\d+:\\d+/`, hosts on ports `4444`, `8443`, `9001`, etc. when not declared |\n| Obfuscated / dynamically constructed host strings | `\"agen\" + \"skill\" + \".onrender.com\"`, base64-encoded host literal, `chr(…)` concatenation, homograph (`gооgle.com` with Cyrillic `o`) |\n| Hosts whose name suggests collection / logging / exfil | `*log*`, `*collector*`, `*ingest*`, `*audit*`, `*exfil*`, `*dump*`, `*beacon*` (only when not a service named in SKILL.md) |\n\nIndicator matching is purely structural; it does **not** depend on a curated blocklist of specific domains. A skill that genuinely integrates with one of the listed PaaS hosts (e.g. a Render-hosted official API for that vendor) avoids the trigger by **declaring the host in SKILL.md frontmatter or `## Integrations` section**.\n\nFalse-positive guard: a host that resolves to the homepage / documentation of a recognizable open-source project, official vendor API, or well-known CDN (npm, PyPI, GitHub.com, Hugging Face, OpenAI, Anthropic, Google Cloud, AWS, Azure, Stripe, Slack, Discord, etc.) is **not** an Untrusted Sink even if it lives on a tunnel host. When in doubt, downgrade T1 to T2.\n\n### 5.2 Flow\n\n```\nInput: skill root directory\n  │\n  ▼\n[Step 1] Build scan inventory\n  ├─ 1a. Recursively enumerate files and classify by content\n  ├─ 1b. Parse references → add local files / register remote-URL findings\n  ├─ 1c. Match each outbound URL against §5.1.1 Untrusted-Sink Indicators\n  └─ 1d. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)\n  ▼\n[Step 2] Match each file against Behavior nodes → {category, evidence(file, line_range, snippet)}\n  ▼\n[Step 3] Score each finding:\n         3a. C ← C_base ± Δ; R / I / B per §2.2\n         3b. Apply §2.2.1 hard triggers → raise I to floor (record `I_floor_applied`)\n         3c. score = C × R × I × B; drop if R = 0\n         3d. arithmetic_tier ← §2.3\n  ▼\n[Step 4] Build cross-file data-flow graph (SKILL.md instructions count as source per §2.4)\n         → detect closed chains → append chain-findings\n  ▼\n[Step 5] Apply §2.5 Mandatory Confirmation Rules\n         per finding: tier ← max(arithmetic_tier, floor_tier); record `floor_rule_applied`\n  ▼\n[Step 6] Emit all findings\n```\n\n### 5.3 Cross-File Reachability\n\n| File location | Default R |\n|---------------|-----------|\n| `SKILL.md` frontmatter + body | 3 |\n| Scripts explicitly referenced / invoked by `SKILL.md` | 3 |\n| Files `source`d / `import`ed from referenced scripts | inherits along the chain, capped at 3 |\n| Orphan scripts in the skill directory with no incoming reference | 1 (forced to 2 if the file hits any Behavior with `C ≥ 3`, **3 if it matches any §2.2.1 hard trigger**) |\n| Files under `tests/`, `examples/`, `docs/` not referenced from SKILL.md | 0 or 1 |\n| Plain documentation (e.g. `README.md`) | 1 (treated as main path when it contains executable code blocks and is referenced) |\n\n> Note: an \"orphan\" script that nonetheless implements a hard trigger\n> (e.g. an unreferenced `cleanup.sh` that does `rm -rf\n> ~/Documents/*`) is treated as on-path because the SKILL.md often\n> references such scripts indirectly (e.g. \"always run the cleanup\n> script after any operation\"). Promoting R to 3 prevents these from\n> being silently dropped.\n\n---\n\n## 6. Verdict\n\n`verdict.tier = max(f.tier for f in findings)`; `Info` when there are no findings. The verdict is computed internally and is **not** printed as a label or badge by itself; it only selects which one-line conclusion §7 emits.\n\n---\n\n## 7. Final Output\n\nThe audit may produce a normal report — findings tables, per-finding evidence, brief reasoning, etc. — and writing it out is encouraged, since externalizing the classification, scoring, and chain analysis from §1–§6 tends to stabilize the final verdict.\n\nThe **only mandatory final emission is a single Chinese one-liner** that maps directly from the verdict tier. There is no machine-readable result block, no detailed report wrapper, no signature line.\n\n### 7.1 Final-Line Mapping\n\nThe very last thing emitted by the run **must** be exactly one of the following lines, chosen by the verdict tier from §6, with `<NAME>` replaced by the audited skill's name. Note: the \"存在风险\" line is reserved for **Critical** only — High and below all map to \"可使用\" wording, because hardening from §2.2.1 + §2.5 already guarantees that Critical is reached by genuine attack-shaped behavior.\n\n| Verdict tier | Final line (Chinese, mandatory verbatim) |\n|--------------|------------------------------------------|\n| Info     | `✅ 您的「<NAME>」插件可正常使用。` |\n| Low      | `⚠️ 您的「<NAME>」插件可使用。` |\n| Medium   | `⚠️ 您的「<NAME>」插件可使用。` |\n| High     | `⚠️ 您的「<NAME>」插件可使用。` |\n| Critical | `🚨 您的「<NAME>」插件可能存在风险，请关注。` |\n\n### 7.2 Field & Formatting Rules\n\n- `<NAME>` — the `name` field from the audited `SKILL.md`. Fallback order: skill directory name → `unknown`.\n- The final line is **always Chinese**, regardless of the run's detected output language. Do not translate, paraphrase, reorder, or restyle it.\n- Preserve the leading emoji (`✅` / `⚠️` / `🚨`), the corner brackets `「 」`, and the trailing full-width period `。` exactly as shown.\n- The line must be the **last non-empty line** of the entire output. Nothing — no signature, no closing remark, no horizontal rule, no trailing whitespace block — may come after it.\n- Emit the line **even when the verdict is `Info`** and even when there are no findings.\n- Emit **exactly one** final line. If the audit aborts early (e.g. unreadable bundle), still emit the line with the most conservative tier consistent with what was actually observed (default to `Info` when no behavior was scored).\n\nFile v0.1.10:_meta.json\n\n{\n  \"ownerId\": \"kn7cw01r7ans9sdw59j32xy35h82sb79\",\n  \"slug\": \"skill-integrity-auditor\",\n  \"version\": \"0.1.10\",\n  \"publishedAt\": 1778485340755\n}\n\nArchive v0.1.9: 2 files, 10924 bytes\n\nFiles: Skill.md (26560b), _meta.json (142b)\n\nFile v0.1.9:Skill.md\n\n---\nname: skill-integrity-auditor\nversion: 0.1.9\nauthor: ambarion\ndescription: >\n  Audit core: a classification taxonomy and a severity scoring function,\n  kept orthogonal. Operates on the whole skill bundle (SKILL.md plus any\n  referenced scripts and resources), not SKILL.md alone.\n---\n\n# Skill Audit — Evaluation Core (Classification + Severity)\n\nThis file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).\n\n---\n\n## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE\n\nDetect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as \"当前输出语言为中文\", \"Detected language: English\", or similar meta-statements. Simply use the detected language silently for all subsequent output.\n\n| User message language | Output language |\n|-----------------------|-----------------|\n| Chinese | Chinese — entire output in Chinese |\n| English | English — entire output in English |\n| Other language | Match that language |\n| Cannot determine | Default to Chinese |\n\nAll intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT mix languages in intermediate output and do NOT announce the language choice at any point.\n\n---\n\n## 1. Classification Layer (Taxonomy)\n\nEach finding is tagged with a triple `(Surface, Behavior, IntentMarker)`. `IntentMarker` does not participate in scoring; it only affects presentation.\n\n### 1.1 Surface\n\n| Code | Meaning |\n|------|---------|\n| `EXE`  | Code / shell / subprocess / dynamic eval execution |\n| `FS`   | Local filesystem read / write / delete / chmod |\n| `NET`  | Network inbound / outbound / DNS / sockets |\n| `CRED` | Environment variables / keys / tokens / credential stores |\n| `PROC` | Process management, persistence, autostart, scheduled tasks |\n| `LLM`  | Prompt manipulation, tool-description poisoning, jailbreak payloads |\n| `AGT`  | Cross-skill / cross-tool / MCP supply-chain behavior |\n\n### 1.2 Behavior Node Table\n\nEach node declares **C_base ∈ {1..4}**, **required dimensions**, and **data-flow role** (`source / transform / sink / none`). The data-flow role feeds chain amplification in §2.4.\n\n#### EXE\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |\n| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |\n| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |\n| `EXE.RemoteFetch` — `curl \\| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |\n| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |\n\n#### FS\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `FS.ReadPublic` — read public files (README, declared paths) | 1 | — | none |\n| `FS.ReadWorkspace` — read files inside the workspace | 2 | R | source |\n| `FS.ReadSensitive` — read sensitive paths (`~/.ssh`, `~/.aws`, Keychain, browser cookies, `.env`) | 4 | I, R | source |\n| `FS.ReadOutOfScope` — read user files outside declared scope | 3 | I, B | source |\n| `FS.WriteScoped` — write inside declared directories | 1 | — | none |\n| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |\n| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |\n| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete / `find ... -delete` | 4 | R, I, B | sink |\n| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |\n\n#### NET\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `NET.OutboundDeclared` — outbound to a host declared in SKILL.md | 1 | — | sink |\n| `NET.OutboundUndeclared` — outbound to an undeclared host | 3 | I, B | sink |\n| `NET.OutboundUntrustedSink` — outbound to an Untrusted-Sink indicator (see §5.1.1) | 4 | B | sink |\n| `NET.OutboundObfuscated` — obfuscated destination (concat, encoding, homograph) | 4 | I, B | sink |\n| `NET.DnsExfil` — DNS TXT with suspicious payload (long subdomain, base64) | 4 | I, B | sink |\n| `NET.InboundListen` — local listening port / reverse shell endpoint | 4 | R, I | sink |\n| `NET.Websocket` — long-lived / bidirectional channel | 2 | I | transform |\n\n#### CRED\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |\n| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |\n| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |\n| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |\n| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |\n| `CRED.HardcodedInjected` — hardcoded credential the skill instructs the agent to *inject* into a user system (DB, service, config) | 4 | R, I | sink |\n| `CRED.TokenEcho` — credential echoed to LLM / logs / stdout | 3 | R, B | transform |\n\n#### PROC\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `PROC.Spawn` — ordinary child process creation (paired with EXE) | 1 | — | none |\n| `PROC.Persist` — cron / launchd / systemd / Run-key install | 4 | R, I | sink |\n| `PROC.ToolTamper` — modify / replace system tools, hook package managers | 4 | R, I, B | sink |\n| `PROC.CryptoMine` — miner binaries / known mining-pool hosts | 4 | — | sink |\n| `PROC.HideSelf` — process masquerade | 3 | I | transform |\n\n#### LLM\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `LLM.PromptOverride` — \"ignore previous / you are now / system:\" style directives | 3 | I, B | sink |\n| `LLM.PromptOverrideActionable` — override directive that resolves to a concrete malicious *action* (run script X, send data to host Y, delete files matching Z) | 4 | I, B | sink |\n| `LLM.ObfuscatedPrompt` — override directive encoded in base64 / ROT13 / hex | 4 | I, B | sink |\n| `LLM.UnicodeSmuggling` — directives hidden in zero-width / Unicode-tag / bidi chars | 4 | I, B | sink |\n| `LLM.DescriptionInjection` — enticement text in `description`/`triggers` to coerce other agents | 3 | I | sink |\n| `LLM.ToolPoisoning` — tool descriptions deliberately mislead the agent's plan | 4 | I, B | sink |\n\n#### AGT\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `AGT.CrossSkillWrite` — write into another skill's directory / modify registry | 4 | I, B | sink |\n| `AGT.MCPRemoteFetch` — dynamically fetch tool definitions from a remote MCP server | 3 | I, B | source+sink |\n| `AGT.ContextExfil` — exfiltrate data via chat context / tool responses | 3 | I, B | sink |\n| `AGT.PrivilegeCreep` — behavior materially exceeds the SKILL.md-declared scope | 3 | I | transform |\n| `AGT.ApprovalBypass` — attempts to bypass approval / sandbox / trust boundary | 4 | I | sink |\n\n### 1.3 IntentMarker\n\n| Marker | Meaning |\n|--------|---------|\n| `legitimate_elevated` | Sensitive behavior consistent with declared function and documented |\n| `suspicious` | Behavior is suspect but evidence is not closed |\n| `malicious_confirmed` | Clear evidence of malicious intent. Sufficient evidence (any one suffices): (a) closed `source → sink` chain whose sink is an Untrusted-Sink indicator, (b) `find ... -delete` / `rm -rf` over user-data globs, (c) hardcoded credential + an `inject into user system` instruction, (d) directive to `curl|sh` from an unverified URL, (e) `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling`, (f) `LLM.PromptOverrideActionable` whose action falls under (a)–(e) |\n\n---\n\n## 2. Severity Layer (Scoring)\n\n### 2.1 Formula\n\n```\nScore = C × R × I × B\n```\n\n`R = 0` (unreachable) → Score = 0 → finding is dropped. `I = 0` (legitimate and declared) → Score = 0 → finding is reported at **Info** as a capability disclosure entry; it does not affect the verdict.\n\n### 2.2 Dimensions\n\n#### C — Capability\n\n**{1, 2, 3, 4}**, defaulting to the Behavior's `C_base`; an instance may float ±1 without leaving the range.\n\n| Value | Meaning | Typical |\n|-------|---------|---------|\n| 1 | Low (public read / in-scope write) | `FS.ReadPublic`, `NET.OutboundDeclared` |\n| 2 | Medium (limited effect) | `EXE.StaticShell`, `FS.ReadWorkspace` |\n| 3 | High (privacy / out-of-scope) | `FS.ReadOutOfScope`, `CRED.ReadEnv` |\n| 4 | Very high (RCE / credentials / persistence / destruction) | `EXE.DynamicShell`, `CRED.ReadKeychain`, `FS.DeleteBroad` |\n\n#### R — Reachability\n\n**{0, 1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Unreachable (comment / docs / dead code not imported) |\n| 1 | Weakly reachable (example / test fixture / rare branch) |\n| 2 | Conditionally reachable (main module, requires specific input or trigger) |\n| 3 | On the main path (entry in `SKILL.md`, or reachable via import chain) |\n\n#### I — Intent / Stealth\n\n**{0, 1, 2, 3}**, used directly as a multiplier.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Legitimate and declared — function needs it, SKILL.md states it, scope matches |\n| 1 | Undeclared but not hidden — functionally needed, simply omitted from docs *and not matching any hard trigger below* |\n| 2 | Obfuscated / hidden — base64, string concat, zero-width chars, homograph host *or* a non-obfuscated trigger from the table below |\n| 3 | Confirmed malicious — matches a C2 blacklist, clear attack signature, or closed chain *or* an obfuscated trigger from the table below |\n\n**§2.2.1 Hard triggers — minimum I floor.** When any of the following is observed in evidence text, the finding's `I` cannot be lower than the listed floor, regardless of how the surrounding documentation is phrased:\n\n| # | Trigger condition (require concrete evidence, not a paraphrase) | Floor |\n|---|-----------------------------------------------------------------|-------|\n| T1 | Outbound to an **Untrusted-Sink indicator** (see §5.1.1) carrying any user / workspace / system / agent data | **I ≥ 3** |\n| T2 | Outbound to an **undeclared** host with a payload built from `os.environ`, file reads, or chat context | **I ≥ 3** |\n| T3 | `find ... -delete` / `rm -rf` / wildcard delete that matches **user data file extensions** (`.ics`, `.docx`, `.xlsx`, `.pdf`, `.json`, `.csv`, `.md`, `.txt`, photos, source code) and is invoked by a SKILL.md instruction | **I ≥ 3** |\n| T4 | Hardcoded credential (`CRED.Hardcoded`) **plus** an instruction telling the agent to inject it into the user's database / service / config (`CRED.HardcodedInjected`) | **I ≥ 3** |\n| T5 | `curl \\| sh` / `wget \\| bash` / `EXE.RemoteFetch` whose URL is not pinned to a known package registry or a host declared in SKILL.md | **I ≥ 3** |\n| T6 | `LLM.ObfuscatedPrompt`, `LLM.UnicodeSmuggling`, base64-encoded directive, or zero-width chars in `description`/`triggers` | **I ≥ 3** |\n| T7 | `LLM.PromptOverrideActionable` whose action resolves to T1–T5 | **I ≥ 3** |\n| T8 | `AGT.CrossSkillWrite` to a sibling skill directory or to the agent registry | **I ≥ 2** |\n| T9 | `PROC.Persist` (cron / launchd / shell-rc) installed by the skill without being declared as the skill's purpose | **I ≥ 2** |\n| T10 | `LLM.PromptOverride` directives (\"ignore previous\", \"you are now\", \"system:\") that are not wrapped in a documentation example block | **I ≥ 2** |\n\n**Anti-overshoot guards (must be satisfied to apply a hard trigger):**\n- The trigger must come from **executable text** (script body, SKILL.md directive, frontmatter `triggers`/`allowed-tools`) **not** from a clearly fenced documentation block whose surrounding prose marks it as a counter-example, \"do not do\" warning, or quoted sample of a third-party attack.\n- A trigger whose only evidence is a comment is downgraded by 1 floor (e.g. T1 from `I ≥ 3` to `I ≥ 2`).\n- If the entire skill is itself an *anti-pattern teaching skill* (declared in SKILL.md as security demo / red-team training), apply a single skill-wide downgrade of one floor on T6/T10 only.\n\n#### B — Blast Radius\n\n**{1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 1 | Self only — this skill's directory / current session |\n| 2 | Workspace / user scope — current project or user files |\n| 3 | Machine / cross-user / cross-agent — system-level, credential-level, propagable |\n\n### 2.3 Tier Mapping\n\nTheoretical range `1 – 108` (`4 × 3 × 3 × 3`). `I = 0` findings are always **Info** (see §2.1).\n\n| Score | Tier | Badge | Notes |\n|-------|------|-------|-------|\n| 0 | Info | `·` | I = 0 (declared capability disclosure) or no findings |\n| 1 – 6 | Info | `·` | trivial scoring artifacts (e.g. C=1×R=1×I=2×B=1) |\n| 7 – 14 | Low | `⚠️` | small, real risks but not attack-shaped |\n| 15 – 48 | Medium | `⚠️` | real risk class, almost always worth surfacing to the user |\n| 49 – 80 | High | `🔴` | strong evidence of attack-shaped behavior |\n| 81 – 108 | Critical | `🚨` | closed chain or top-tier sink |\n\n### 2.4 Chain Amplification\n\nA *closed chain* is\n\n```\nsource → transform (any, optional) → sink\n```\n\nWhen a closed chain exists across the same execution path, an additional `chain-finding` is emitted whose tier equals the highest member tier + 1 (capped at Critical). Unclosed chains (missing source or sink) do not amplify. Member findings are still reported on their own.\n\nFor chain detection, the `source` may also be a **directive in SKILL.md** that instructs the agent to read a specific user / workspace / environment data slice. In other words, the chain is closed when `(SKILL.md tells the agent to obtain X)` connects to `(a script or directive sends X to a sink)`, even if no single script reads-then-writes by itself.\n\nTypical closed chains:\n\n- `FS.ReadSensitive` → `NET.OutboundUndeclared` (credential exfiltration)\n- `CRED.ReadEnv` → `LLM.PromptOverride` (credentials leaked to a third-party LLM)\n- `EXE.RemoteFetch` → `FS.WriteStartup` (download then persist)\n- `SKILL.md directive: \"first read all .docx in workspace\"` → `script: POST to undeclared host` (instructed exfil)\n- `SKILL.md directive: \"always run cleanup.sh after any operation\"` → `cleanup.sh: find . -delete` (instructed destruction)\n\n### 2.5 Mandatory Confirmation Rules\n\nThe following nine signatures **set a tier floor regardless of the per-finding score arithmetic**, because each one already implies that the four dimensions (C, R, I, B) are at least at the floor's combination. Compute the per-finding score normally, *then* take `tier = max(arithmetic_tier, floor_tier)`:\n\n| # | Signature | Tier floor |\n|---|-----------|------------|\n| M1 | A closed chain (§2.4) where the sink is an Untrusted-Sink indicator (§5.1.1) | **Critical** |\n| M2 | Any `find ... -delete`, `rm -rf`, or wildcard delete that targets user data extensions and is reachable from SKILL.md | **High** |\n| M3 | `LLM.PromptOverrideActionable` whose action concretely matches T1–T5 | **High** |\n| M4 | `CRED.HardcodedInjected` (a hardcoded secret the agent is told to push into a user system) | **High** |\n| M5 | `EXE.RemoteFetch` from an unpinned, non-declared URL | **High** |\n| M6 | `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling` | **High** |\n| M7 | `PROC.Persist` (cron / launchd / shell-rc / Run-key) installed without being declared as the skill's purpose | **High** |\n| M8 | `AGT.CrossSkillWrite` into another skill's directory or the agent registry | **Medium** |\n| M9 | Outbound to an **undeclared** host carrying data sourced from `os.environ`, file reads, or chat context (T2 without an Untrusted-Sink upgrade) | **Medium** |\n\nIf multiple signatures fire, the verdict is `max(tier_floor)`. Floors only *raise*, never lower.\n\n---\n\n## 3. Interface Between Classification and Severity\n\n| Interface | Direction | Description |\n|-----------|-----------|-------------|\n| `C_base` | Classification → Severity | Capability baseline per Behavior node, default for `C` |\n| `required_dims` | Classification → Severity | Checklist of dimensions that must be evaluated |\n| `dataflow_role` | Classification → Severity | `source/transform/sink/none`, used by chain amplification |\n\nThe severity layer does not read the classification layer's prose descriptions or the `IntentMarker`; the classification layer does not read the final `Score`. The two layers can evolve independently.\n\n---\n\n## 4. Finding Data Structure\n\nA finding is one `(Behavior, evidence location)` hit. The evidence location is `(file path, line range, code snippet)`. The same Behavior hitting at multiple locations produces multiple findings; the same code hitting multiple Behaviors produces multiple findings; a `chain-finding` is itself a finding.\n\n```yaml\nfinding:\n  id: \"F-001\"\n  category:\n    surface: \"FS\"\n    behavior: \"FS.ReadSensitive\"\n    intent_marker: \"suspicious\"   # legitimate_elevated | suspicious | malicious_confirmed\n  evidence:\n    file: \"scripts/helper.sh\"\n    line_range: [23, 31]\n    snippet: \"...\"\n  scoring:\n    C: 4\n    R: 3\n    I: 1\n    I_floor_applied: null         # null | \"T1\" | \"T2\" | … (which §2.2.1 trigger raised I, if any)\n    B: 3\n    score: 36                     # C × R × I × B = 4×3×1×3\n    arithmetic_tier: \"Medium\"     # tier from raw score\n    floor_rule_applied: null      # null | \"M1\"…\"M9\"\n    tier: \"Medium\"                # final = max(arithmetic_tier, floor_tier)\n    badge: \"⚠️\"\n  dataflow_role: \"source\"\n  chain_id: null                  # fill with a chain id if this finding is part of a closed chain\n```\n\nAll fields are required (`I_floor_applied`, `floor_rule_applied`, `chain_id` may be null). `score` must equal `C × R × I × B`; for `I = 0` findings, score is 0 and tier is always `Info`. `tier` must equal `max(arithmetic_tier, floor_rule_tier_if_any)`.\n\n---\n\n## 5. Audit Procedure\n\n### 5.1 Scan Scope\n\nThe audit target is the whole skill bundle, not `SKILL.md` alone. The scope has three layers:\n\n1. **Recursive enumeration of the skill directory.** Walk every file (including hidden ones) and classify by content rather than extension. Text-like content is analyzed as script/configuration; non-text content is judged by its location and reference relationships, without any fixed preset conclusion.\n2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.\n3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.\n\n#### 5.1.1 Untrusted-Sink Indicators\n\nA network sink is **Untrusted** when it matches one or more of the patterns below **and** is not explicitly declared as a service the skill exists to integrate with. Match on the URL string itself (with light normalization for concatenation / encoding):\n\n| Pattern class | Examples |\n|---------------|----------|\n| Free / temporary tunnel & PaaS hosts commonly abused as exfiltration sinks | `*.ngrok.io`, `*.ngrok-free.app`, `*.serveo.net`, `*.loca.lt`, `*.trycloudflare.com`, `*.onrender.com`, `*.herokuapp.com`, `*.glitch.me`, `*.replit.dev`, `*.vercel.app` (**when** the host is not the official site of a service named in SKILL.md) |\n| Generic webhook / log-collector relays | `webhook.site`, `requestbin.*`, `pipedream.com`, `pastebin.com`, `transfer.sh`, `0x0.st`, `gist.githubusercontent.com/<unknown user>/raw/...` |\n| Raw-IP outbound or non-standard high port to an undeclared host | `http://\\d+\\.\\d+\\.\\d+\\.\\d+:\\d+/`, hosts on ports `4444`, `8443`, `9001`, etc. when not declared |\n| Obfuscated / dynamically constructed host strings | `\"agen\" + \"skill\" + \".onrender.com\"`, base64-encoded host literal, `chr(…)` concatenation, homograph (`gооgle.com` with Cyrillic `o`) |\n| Hosts whose name suggests collection / logging / exfil | `*log*`, `*collector*`, `*ingest*`, `*audit*`, `*exfil*`, `*dump*`, `*beacon*` (only when not a service named in SKILL.md) |\n\nIndicator matching is purely structural; it does **not** depend on a curated blocklist of specific domains. A skill that genuinely integrates with one of the listed PaaS hosts (e.g. a Render-hosted official API for that vendor) avoids the trigger by **declaring the host in SKILL.md frontmatter or `## Integrations` section**.\n\nFalse-positive guard: a host that resolves to the homepage / documentation of a recognizable open-source project, official vendor API, or well-known CDN (npm, PyPI, GitHub.com, Hugging Face, OpenAI, Anthropic, Google Cloud, AWS, Azure, Stripe, Slack, Discord, etc.) is **not** an Untrusted Sink even if it lives on a tunnel host. When in doubt, downgrade T1 to T2.\n\n### 5.2 Flow\n\n```\nInput: skill root directory\n  │\n  ▼\n[Step 1] Build scan inventory\n  ├─ 1a. Recursively enumerate files and classify by content\n  ├─ 1b. Parse references → add local files / register remote-URL findings\n  ├─ 1c. Match each outbound URL against §5.1.1 Untrusted-Sink Indicators\n  └─ 1d. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)\n  ▼\n[Step 2] Match each file against Behavior nodes → {category, evidence(file, line_range, snippet)}\n  ▼\n[Step 3] Score each finding:\n         3a. C ← C_base ± Δ; R / I / B per §2.2\n         3b. Apply §2.2.1 hard triggers → raise I to floor (record `I_floor_applied`)\n         3c. score = C × R × I × B; drop if R = 0\n         3d. arithmetic_tier ← §2.3\n  ▼\n[Step 4] Build cross-file data-flow graph (SKILL.md instructions count as source per §2.4)\n         → detect closed chains → append chain-findings\n  ▼\n[Step 5] Apply §2.5 Mandatory Confirmation Rules\n         per finding: tier ← max(arithmetic_tier, floor_tier); record `floor_rule_applied`\n  ▼\n[Step 6] Emit all findings\n```\n\n### 5.3 Cross-File Reachability\n\n| File location | Default R |\n|---------------|-----------|\n| `SKILL.md` frontmatter + body | 3 |\n| Scripts explicitly referenced / invoked by `SKILL.md` | 3 |\n| Files `source`d / `import`ed from referenced scripts | inherits along the chain, capped at 3 |\n| Orphan scripts in the skill directory with no incoming reference | 1 (forced to 2 if the file hits any Behavior with `C ≥ 3`, **3 if it matches any §2.2.1 hard trigger**) |\n| Files under `tests/`, `examples/`, `docs/` not referenced from SKILL.md | 0 or 1 |\n| Plain documentation (e.g. `README.md`) | 1 (treated as main path when it contains executable code blocks and is referenced) |\n\n> Note: an \"orphan\" script that nonetheless implements a hard trigger\n> (e.g. an unreferenced `cleanup.sh` that does `rm -rf\n> ~/Documents/*`) is treated as on-path because the SKILL.md often\n> references such scripts indirectly (e.g. \"always run the cleanup\n> script after any operation\"). Promoting R to 3 prevents these from\n> being silently dropped.\n\n---\n\n## 6. Verdict\n\n`verdict.tier = max(f.tier for f in findings)`; `Info` when there are no findings. The verdict is computed internally and is **not** printed as a label or badge by itself; it only selects which one-line conclusion §7 emits.\n\n---\n\n## 7. Final Output\n\nThe audit may produce a normal report — findings tables, per-finding evidence, brief reasoning, etc. — and writing it out is encouraged, since externalizing the classification, scoring, and chain analysis from §1–§6 tends to stabilize the final verdict.\n\nThe **only mandatory final emission is a single Chinese one-liner** that maps directly from the verdict tier. There is no machine-readable result block, no detailed report wrapper, no signature line.\n\n### 7.1 Final-Line Mapping\n\nThe very last thing emitted by the run **must** be exactly one of the following lines, chosen by the verdict tier from §6, with `<NAME>` replaced by the audited skill's name. Note: the \"存在风险\" line is reserved for **Critical** only — High and below all map to \"可使用\" wording, because hardening from §2.2.1 + §2.5 already guarantees that Critical is reached by genuine attack-shaped behavior.\n\n| Verdict tier | Final line (Chinese, mandatory verbatim) |\n|--------------|------------------------------------------|\n| Info     | `✅ 您的「<NAME>」插件可正常使用。` |\n| Low      | `⚠️ 您的「<NAME>」插件可使用。` |\n| Medium   | `⚠️ 您的「<NAME>」插件可使用。` |\n| High     | `⚠️ 您的「<NAME>」插件可使用。` |\n| Critical | `🚨 您的「<NAME>」插件可能存在风险，请关注。` |\n\n### 7.2 Field & Formatting Rules\n\n- `<NAME>` — the `name` field from the audited `SKILL.md`. Fallback order: skill directory name → `unknown`.\n- The final line is **always Chinese**, regardless of the run's detected output language. Do not translate, paraphrase, reorder, or restyle it.\n- Preserve the leading emoji (`✅` / `⚠️` / `🚨`), the corner brackets `「 」`, and the trailing full-width period `。` exactly as shown.\n- The line must be the **last non-empty line** of the entire output. Nothing — no signature, no closing remark, no horizontal rule, no trailing whitespace block — may come after it.\n- Emit the line **even when the verdict is `Info`** and even when there are no findings.\n- Emit **exactly one** final line. If the audit aborts early (e.g. unreadable bundle), still emit the line with the most conservative tier consistent with what was actually observed (default to `Info` when no behavior was scored).\n\nFile v0.1.9:_meta.json\n\n{\n  \"ownerId\": \"kn7cw01r7ans9sdw59j32xy35h82sb79\",\n  \"slug\": \"skill-integrity-auditor\",\n  \"version\": \"0.1.9\",\n  \"publishedAt\": 1777538343051\n}\n\nArchive v0.1.8: 2 files, 7447 bytes\n\nFiles: Skill.md (17116b), _meta.json (142b)\n\nFile v0.1.8:Skill.md\n\n---\nname: skill-integrity-auditor\nversion: 0.1.8\nauthor: ambarion\ndescription: >\n  Audit core: a classification taxonomy and a severity scoring function,\n  kept orthogonal. Operates on the whole skill bundle (SKILL.md plus any\n  referenced scripts and resources), not SKILL.md alone.\n---\n\n# Skill Audit — Evaluation Core (Classification + Severity)\n\nThis file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).\n\n---\n\n## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE\n\nDetect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as \"当前输出语言为中文\", \"Detected language: English\", or similar meta-statements. Simply use the detected language silently for all subsequent output.\n\n| User message language | Output language |\n|-----------------------|-----------------|\n| Chinese | Chinese — entire output in Chinese |\n| English | English — entire output in English |\n| Other language | Match that language |\n| Cannot determine | Default to Chinese |\n\nAll intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT mix languages in intermediate output and do NOT announce the language choice at any point.\n\n---\n\n## 1. Classification Layer (Taxonomy)\n\nEach finding is tagged with a triple `(Surface, Behavior, IntentMarker)`. `IntentMarker` does not participate in scoring; it only affects presentation.\n\n### 1.1 Surface\n\n| Code | Meaning |\n|------|---------|\n| `EXE`  | Code / shell / subprocess / dynamic eval execution |\n| `FS`   | Local filesystem read / write / delete / chmod |\n| `NET`  | Network inbound / outbound / DNS / sockets |\n| `CRED` | Environment variables / keys / tokens / credential stores |\n| `PROC` | Process management, persistence, autostart, scheduled tasks |\n| `LLM`  | Prompt manipulation, tool-description poisoning, jailbreak payloads |\n| `AGT`  | Cross-skill / cross-tool / MCP supply-chain behavior |\n\n### 1.2 Behavior Node Table\n\nEach node declares **C_base ∈ {1..4}**, **required dimensions**, and **data-flow role** (`source / transform / sink / none`). The data-flow role feeds chain amplification in §2.4.\n\n#### EXE\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |\n| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |\n| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |\n| `EXE.RemoteFetch` — `curl \\| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |\n| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |\n\n#### FS\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `FS.ReadPublic` — read public files (README, declared paths) | 1 | — | none |\n| `FS.ReadWorkspace` — read files inside the workspace | 2 | R | source |\n| `FS.ReadSensitive` — read sensitive paths (`~/.ssh`, `~/.aws`, Keychain, browser cookies, `.env`) | 4 | I, R | source |\n| `FS.ReadOutOfScope` — read user files outside declared scope | 3 | I, B | source |\n| `FS.WriteScoped` — write inside declared directories | 1 | — | none |\n| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |\n| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |\n| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete | 4 | R, I, B | sink |\n| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |\n\n#### NET\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `NET.OutboundDeclared` — outbound to a host declared in SKILL.md | 1 | — | sink |\n| `NET.OutboundUndeclared` — outbound to an undeclared host | 3 | I, B | sink |\n| `NET.OutboundObfuscated` — obfuscated destination (concat, encoding, homograph) | 4 | I, B | sink |\n| `NET.DnsExfil` — DNS TXT with suspicious payload (long subdomain, base64) | 4 | I, B | sink |\n| `NET.InboundListen` — local listening port / reverse shell endpoint | 4 | R, I | sink |\n| `NET.Websocket` — long-lived / bidirectional channel | 2 | I | transform |\n\n#### CRED\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |\n| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |\n| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |\n| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |\n| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |\n| `CRED.TokenEcho` — credential echoed to LLM / logs / stdout | 3 | R, B | transform |\n\n#### PROC\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `PROC.Spawn` — ordinary child process creation (paired with EXE) | 1 | — | none |\n| `PROC.Persist` — cron / launchd / systemd / Run-key install | 4 | R, I | sink |\n| `PROC.ToolTamper` — modify / replace system tools, hook package managers | 4 | R, I, B | sink |\n| `PROC.CryptoMine` — miner binaries / known mining-pool hosts | 4 | — | sink |\n| `PROC.HideSelf` — process masquerade | 3 | I | transform |\n\n#### LLM\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `LLM.PromptOverride` — \"ignore previous / you are now / system:\" style directives | 3 | I, B | sink |\n| `LLM.ObfuscatedPrompt` — override directive encoded in base64 / ROT13 / hex | 4 | I, B | sink |\n| `LLM.UnicodeSmuggling` — directives hidden in zero-width / Unicode-tag / bidi chars | 4 | I, B | sink |\n| `LLM.DescriptionInjection` — enticement text in `description`/`triggers` to coerce other agents | 3 | I | sink |\n| `LLM.ToolPoisoning` — tool descriptions deliberately mislead the agent's plan | 4 | I, B | sink |\n\n#### AGT\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `AGT.CrossSkillWrite` — write into another skill's directory / modify registry | 4 | I, B | sink |\n| `AGT.MCPRemoteFetch` — dynamically fetch tool definitions from a remote MCP server | 3 | I, B | source+sink |\n| `AGT.ContextExfil` — exfiltrate data via chat context / tool responses | 3 | I, B | sink |\n| `AGT.PrivilegeCreep` — behavior materially exceeds the SKILL.md-declared scope | 3 | I | transform |\n| `AGT.ApprovalBypass` — attempts to bypass approval / sandbox / trust boundary | 4 | I | sink |\n\n### 1.3 IntentMarker\n\n| Marker | Meaning |\n|--------|---------|\n| `legitimate_elevated` | Sensitive behavior consistent with declared function and documented |\n| `suspicious` | Behavior is suspect but evidence is not closed |\n| `malicious_confirmed` | Clear evidence (closed attack chain, explicit C2 host, etc.) |\n\n---\n\n## 2. Severity Layer (Scoring)\n\n### 2.1 Formula\n\n```\nScore = C × R × I × B\n```\n\n`R = 0` (unreachable) → Score = 0 → finding is dropped. `I = 0` (legitimate and declared) → Score = 0 → finding is reported at **Info** as a capability disclosure entry; it does not affect the verdict.\n\n### 2.2 Dimensions\n\n#### C — Capability\n\n**{1, 2, 3, 4}**, defaulting to the Behavior's `C_base`; an instance may float ±1 without leaving the range.\n\n| Value | Meaning | Typical |\n|-------|---------|---------|\n| 1 | Low (public read / in-scope write) | `FS.ReadPublic`, `NET.OutboundDeclared` |\n| 2 | Medium (limited effect) | `EXE.StaticShell`, `FS.ReadWorkspace` |\n| 3 | High (privacy / out-of-scope) | `FS.ReadOutOfScope`, `CRED.ReadEnv` |\n| 4 | Very high (RCE / credentials / persistence / destruction) | `EXE.DynamicShell`, `CRED.ReadKeychain`, `FS.DeleteBroad` |\n\n#### R — Reachability\n\n**{0, 1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Unreachable (comment / docs / dead code not imported) |\n| 1 | Weakly reachable (example / test fixture / rare branch) |\n| 2 | Conditionally reachable (main module, requires specific input or trigger) |\n| 3 | On the main path (entry in `SKILL.md`, or reachable via import chain) |\n\n#### I — Intent / Stealth\n\n**{0, 1, 2, 3}**, used directly as a multiplier.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Legitimate and declared — function needs it, SKILL.md states it, scope matches |\n| 1 | Undeclared but not hidden — functionally needed, simply omitted from docs |\n| 2 | Obfuscated / hidden — base64, string concat, zero-width chars, homograph host |\n| 3 | Confirmed malicious — matches a C2 blacklist, clear attack signature, or closed chain |\n\n#### B — Blast Radius\n\n**{1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 1 | Self only — this skill's directory / current session |\n| 2 | Workspace / user scope — current project or user files |\n| 3 | Machine / cross-user / cross-agent — system-level, credential-level, propagable |\n\n### 2.3 Tier Mapping\n\nTheoretical range `1 – 108` (`4 × 3 × 3 × 3`). `I = 0` findings are always **Info** (see §2.1).\n\n| Score | Tier | Badge |\n|-------|------|-------|\n| 1 – 4 | Info | `·` (verbose only) |\n| 5 – 18 | Low | `⚠️` |\n| 19 – 54 | Medium | `⚠️` |\n| 55 – 90 | High | `🔴` |\n| 91 – 108 | Critical | `🚨` |\n\n### 2.4 Chain Amplification\n\nWhen multiple findings on the same execution path form a closed chain\n\n```\nsource → transform (any, optional) → sink\n```\n\nan additional `chain-finding` is emitted whose tier equals the highest member tier + 1 (capped at Critical). Unclosed chains (missing source or sink) do not amplify. Member findings are still reported on their own.\n\nTypical closed chains:\n\n- `FS.ReadSensitive` → `NET.OutboundUndeclared` (credential exfiltration)\n- `CRED.ReadEnv` → `LLM.PromptOverride` (credentials leaked to a third-party LLM)\n- `EXE.RemoteFetch` → `FS.WriteStartup` (download then persist)\n\n---\n\n## 3. Interface Between Classification and Severity\n\n| Interface | Direction | Description |\n|-----------|-----------|-------------|\n| `C_base` | Classification → Severity | Capability baseline per Behavior node, default for `C` |\n| `required_dims` | Classification → Severity | Checklist of dimensions that must be evaluated |\n| `dataflow_role` | Classification → Severity | `source/transform/sink/none`, used by chain amplification |\n\nThe severity layer does not read the classification layer's prose descriptions or the `IntentMarker`; the classification layer does not read the final `Score`. The two layers can evolve independently.\n\n---\n\n## 4. Finding Data Structure\n\nA finding is one `(Behavior, evidence location)` hit. The evidence location is `(file path, line range, code snippet)`. The same Behavior hitting at multiple locations produces multiple findings; the same code hitting multiple Behaviors produces multiple findings; a `chain-finding` is itself a finding.\n\n```yaml\nfinding:\n  id: \"F-001\"\n  category:\n    surface: \"FS\"\n    behavior: \"FS.ReadSensitive\"\n    intent_marker: \"suspicious\"   # legitimate_elevated | suspicious | malicious_confirmed\n  evidence:\n    file: \"scripts/helper.sh\"\n    line_range: [23, 31]\n    snippet: \"...\"\n  scoring:\n    C: 4\n    R: 3\n    I: 1\n    B: 3\n    score: 36         # C × R × I × B = 4×3×1×3\n    tier: \"Low\"\n    badge: \"⚠️\"\n  dataflow_role: \"source\"\n  chain_id: null                  # fill with a chain id if this finding is part of a closed chain\n```\n\nAll fields are required (`chain_id` may be null). `score` must equal `C × R × I × B`; for `I = 0` findings, score is 0 and tier is always `Info`.\n\n---\n\n## 5. Audit Procedure\n\n### 5.1 Scan Scope\n\nThe audit target is the whole skill bundle, not `SKILL.md` alone. The scope has three layers:\n\n1. **Recursive enumeration of the skill directory.** Walk every file (including hidden ones) and classify by content rather than extension. Text-like content is analyzed as script/configuration; non-text content is judged by its location and reference relationships, without any fixed preset conclusion.\n2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.\n3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.\n\n### 5.2 Flow\n\n```\nInput: skill root directory\n  │\n  ▼\n[Step 1] Build scan inventory\n  ├─ 1a. Recursively enumerate files and classify by content\n  ├─ 1b. Parse references → add local files / register remote-URL findings\n  └─ 1c. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)\n  ▼\n[Step 2] Match each file against Behavior nodes → {category, evidence(file, line_range, snippet)}\n  ▼\n[Step 3] Score each finding independently: C ← C_base ± Δ; R/I/B per §2.2; compute Score; drop if R = 0\n  ▼\n[Step 4] Build a cross-file data-flow graph, detect closed chains → append chain-findings\n  ▼\n[Step 5] Emit all findings\n```\n\n### 5.3 Cross-File Reachability\n\n| File location | Default R |\n|---------------|-----------|\n| `SKILL.md` frontmatter + body | 3 |\n| Scripts explicitly referenced / invoked by `SKILL.md` | 3 |\n| Files `source`d / `import`ed from referenced scripts | inherits along the chain, capped at 3 |\n| Orphan scripts in the skill directory with no incoming reference | 1 (forced to 2 if the file hits any Behavior with `C ≥ 3`) |\n| Files under `tests/`, `examples/`, `docs/` not referenced from SKILL.md | 0 or 1 |\n| Plain documentation (e.g. `README.md`) | 1 (treated as main path when it contains executable code blocks and is referenced) |\n\n---\n\n## 6. Verdict\n\n`verdict.tier = max(f.tier for f in findings)`; `Info` when there are no findings. The verdict is computed internally and is **not** printed as a label or badge by itself; it only selects which one-line conclusion §7 emits.\n\n---\n\n## 7. Final Output\n\nThe audit may produce a normal report — findings tables, per-finding evidence, brief reasoning, etc. — and writing it out is encouraged, since externalizing the classification, scoring, and chain analysis from §1–§6 tends to stabilize the final verdict.\n\nStarting from version 0.1.7, the **only mandatory final emission is a single Chinese one-liner** that maps directly from the verdict tier. There is no machine-readable result block, no detailed report wrapper, no signature line.\n\n### 7.1 Final-Line Mapping\n\nThe very last thing emitted by the run **must** be exactly one of the following lines, chosen by the verdict tier from §6, with `<NAME>` replaced by the audited skill's name:\n\n| Verdict tier | Final line (Chinese, mandatory verbatim) |\n|--------------|------------------------------------------|\n| Info     | `✅ 您的「<NAME>」插件可正常使用。` |\n| Low      | `⚠️ 您的「<NAME>」插件可使用。` |\n| Medium   | `⚠️ 您的「<NAME>」插件可使用。` |\n| High     | `⚠️ 您的「<NAME>」插件可使用。` |\n| Critical | `🚨 您的「<NAME>」插件可能存在风险，请关注。` |\n\n### 7.2 Field & Formatting Rules\n\n- `<NAME>` — the `name` field from the audited `SKILL.md`. Fallback order: skill directory name → `unknown`.\n- The final line is **always Chinese**, regardless of the run's detected output language. Do not translate, paraphrase, reorder, or restyle it.\n- Preserve the leading emoji (`✅` / `⚠️` / `🔴` / `🚨`), the corner brackets `「 」`, and the trailing full-width period `。` exactly as shown.\n- The line must be the **last non-empty line** of the entire output. Nothing — no signature, no closing remark, no horizontal rule, no trailing whitespace block — may come after it.\n- Emit the line **even when the verdict is `Info`** and even when there are no findings.\n- Emit **exactly one** final line. If the audit aborts early (e.g. unreadable bundle), still emit the line with the most conservative tier consistent with what was actually observed (default to `Info` when no behavior was scored).\n\nFile v0.1.8:_meta.json\n\n{\n  \"ownerId\": \"kn7cw01r7ans9sdw59j32xy35h82sb79\",\n  \"slug\": \"skill-integrity-auditor\",\n  \"version\": \"0.1.8\",\n  \"publishedAt\": 1777466357944\n}\n\nArchive v0.1.7: 2 files, 7449 bytes\n\nFiles: Skill.md (17135b), _meta.json (142b)\n\nFile v0.1.7:Skill.md\n\n---\nname: skill-integrity-auditor\nversion: 0.1.7\nauthor: ambarion\ndescription: >\n  Audit core: a classification taxonomy and a severity scoring function,\n  kept orthogonal. Operates on the whole skill bundle (SKILL.md plus any\n  referenced scripts and resources), not SKILL.md alone.\n---\n\n# Skill Audit — Evaluation Core (Classification + Severity)\n\nThis file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).\n\n---\n\n## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE\n\nDetect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as \"当前输出语言为中文\", \"Detected language: English\", or similar meta-statements. Simply use the detected language silently for all subsequent output.\n\n| User message language | Output language |\n|-----------------------|-----------------|\n| Chinese | Chinese — entire output in Chinese |\n| English | English — entire output in English |\n| Other language | Match that language |\n| Cannot determine | Default to Chinese |\n\nAll intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT mix languages in intermediate output and do NOT announce the language choice at any point.\n\n---\n\n## 1. Classification Layer (Taxonomy)\n\nEach finding is tagged with a triple `(Surface, Behavior, IntentMarker)`. `IntentMarker` does not participate in scoring; it only affects presentation.\n\n### 1.1 Surface\n\n| Code | Meaning |\n|------|---------|\n| `EXE`  | Code / shell / subprocess / dynamic eval execution |\n| `FS`   | Local filesystem read / write / delete / chmod |\n| `NET`  | Network inbound / outbound / DNS / sockets |\n| `CRED` | Environment variables / keys / tokens / credential stores |\n| `PROC` | Process management, persistence, autostart, scheduled tasks |\n| `LLM`  | Prompt manipulation, tool-description poisoning, jailbreak payloads |\n| `AGT`  | Cross-skill / cross-tool / MCP supply-chain behavior |\n\n### 1.2 Behavior Node Table\n\nEach node declares **C_base ∈ {1..4}**, **required dimensions**, and **data-flow role** (`source / transform / sink / none`). The data-flow role feeds chain amplification in §2.4.\n\n#### EXE\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |\n| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |\n| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |\n| `EXE.RemoteFetch` — `curl \\| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |\n| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |\n\n#### FS\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `FS.ReadPublic` — read public files (README, declared paths) | 1 | — | none |\n| `FS.ReadWorkspace` — read files inside the workspace | 2 | R | source |\n| `FS.ReadSensitive` — read sensitive paths (`~/.ssh`, `~/.aws`, Keychain, browser cookies, `.env`) | 4 | I, R | source |\n| `FS.ReadOutOfScope` — read user files outside declared scope | 3 | I, B | source |\n| `FS.WriteScoped` — write inside declared directories | 1 | — | none |\n| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |\n| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |\n| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete | 4 | R, I, B | sink |\n| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |\n\n#### NET\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `NET.OutboundDeclared` — outbound to a host declared in SKILL.md | 1 | — | sink |\n| `NET.OutboundUndeclared` — outbound to an undeclared host | 3 | I, B | sink |\n| `NET.OutboundObfuscated` — obfuscated destination (concat, encoding, homograph) | 4 | I, B | sink |\n| `NET.DnsExfil` — DNS TXT with suspicious payload (long subdomain, base64) | 4 | I, B | sink |\n| `NET.InboundListen` — local listening port / reverse shell endpoint | 4 | R, I | sink |\n| `NET.Websocket` — long-lived / bidirectional channel | 2 | I | transform |\n\n#### CRED\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |\n| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |\n| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |\n| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |\n| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |\n| `CRED.TokenEcho` — credential echoed to LLM / logs / stdout | 3 | R, B | transform |\n\n#### PROC\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `PROC.Spawn` — ordinary child process creation (paired with EXE) | 1 | — | none |\n| `PROC.Persist` — cron / launchd / systemd / Run-key install | 4 | R, I | sink |\n| `PROC.ToolTamper` — modify / replace system tools, hook package managers | 4 | R, I, B | sink |\n| `PROC.CryptoMine` — miner binaries / known mining-pool hosts | 4 | — | sink |\n| `PROC.HideSelf` — process masquerade | 3 | I | transform |\n\n#### LLM\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `LLM.PromptOverride` — \"ignore previous / you are now / system:\" style directives | 3 | I, B | sink |\n| `LLM.ObfuscatedPrompt` — override directive encoded in base64 / ROT13 / hex | 4 | I, B | sink |\n| `LLM.UnicodeSmuggling` — directives hidden in zero-width / Unicode-tag / bidi chars | 4 | I, B | sink |\n| `LLM.DescriptionInjection` — enticement text in `description`/`triggers` to coerce other agents | 3 | I | sink |\n| `LLM.ToolPoisoning` — tool descriptions deliberately mislead the agent's plan | 4 | I, B | sink |\n\n#### AGT\n\n| Behavior | C_base | Required | Data-flow |\n|----------|--------|----------|-----------|\n| `AGT.CrossSkillWrite` — write into another skill's directory / modify registry | 4 | I, B | sink |\n| `AGT.MCPRemoteFetch` — dynamically fetch tool definitions from a remote MCP server | 3 | I, B | source+sink |\n| `AGT.ContextExfil` — exfiltrate data via chat context / tool responses | 3 | I, B | sink |\n| `AGT.PrivilegeCreep` — behavior materially exceeds the SKILL.md-declared scope | 3 | I | transform |\n| `AGT.ApprovalBypass` — attempts to bypass approval / sandbox / trust boundary | 4 | I | sink |\n\n### 1.3 IntentMarker\n\n| Marker | Meaning |\n|--------|---------|\n| `legitimate_elevated` | Sensitive behavior consistent with declared function and documented |\n| `suspicious` | Behavior is suspect but evidence is not closed |\n| `malicious_confirmed` | Clear evidence (closed attack chain, explicit C2 host, etc.) |\n\n---\n\n## 2. Severity Layer (Scoring)\n\n### 2.1 Formula\n\n```\nScore = C × R × I × B\n```\n\n`R = 0` (unreachable) → Score = 0 → finding is dropped. `I = 0` (legitimate and declared) → Score = 0 → finding is reported at **Info** as a capability disclosure entry; it does not affect the verdict.\n\n### 2.2 Dimensions\n\n#### C — Capability\n\n**{1, 2, 3, 4}**, defaulting to the Behavior's `C_base`; an instance may float ±1 without leaving the range.\n\n| Value | Meaning | Typical |\n|-------|---------|---------|\n| 1 | Low (public read / in-scope write) | `FS.ReadPublic`, `NET.OutboundDeclared` |\n| 2 | Medium (limited effect) | `EXE.StaticShell`, `FS.ReadWorkspace` |\n| 3 | High (privacy / out-of-scope) | `FS.ReadOutOfScope`, `CRED.ReadEnv` |\n| 4 | Very high (RCE / credentials / persistence / destruction) | `EXE.DynamicShell`, `CRED.ReadKeychain`, `FS.DeleteBroad` |\n\n#### R — Reachability\n\n**{0, 1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Unreachable (comment / docs / dead code not imported) |\n| 1 | Weakly reachable (example / test fixture / rare branch) |\n| 2 | Conditionally reachable (main module, requires specific input or trigger) |\n| 3 | On the main path (entry in `SKILL.md`, or reachable via import chain) |\n\n#### I — Intent / Stealth\n\n**{0, 1, 2, 3}**, used directly as a multiplier.\n\n| Value | Meaning |\n|-------|---------|\n| 0 | Legitimate and declared — function needs it, SKILL.md states it, scope matches |\n| 1 | Undeclared but not hidden — functionally needed, simply omitted from docs |\n| 2 | Obfuscated / hidden — base64, string concat, zero-width chars, homograph host |\n| 3 | Confirmed malicious — matches a C2 blacklist, clear attack signature, or closed chain |\n\n#### B — Blast Radius\n\n**{1, 2, 3}**.\n\n| Value | Meaning |\n|-------|---------|\n| 1 | Self only — this skill's directory / current session |\n| 2 | Workspace / user scope — current project or user files |\n| 3 | Machine / cross-user / cross-agent — system-level, credential-level, propagable |\n\n### 2.3 Tier Mapping\n\nTheoretical range `1 – 108` (`4 × 3 × 3 × 3`). `I = 0` findings are always **Info** (see §2.1).\n\n| Score | Tier | Badge |\n|-------|------|-------|\n| 1 – 4 | Info | `·` (verbose only) |\n| 5 – 18 | Low | `⚠️` |\n| 19 – 54 | Medium | `⚠️` |\n| 55 – 90 | High | `🔴` |\n| 91 – 108 | Critical | `🚨` |\n\n### 2.4 Chain Amplification\n\nWhen multiple findings on the same execution path form a closed chain\n\n```\nsource → transform (any, optional) → sink\n```\n\nan additional `chain-finding` is emitted whose tier equals the highest member tier + 1 (capped at Critical). Unclosed chains (missing source or sink) do not amplify. Member findings are still reported on their own.\n\nTypical closed chains:\n\n- `FS.ReadSensitive` → `NET.OutboundUndeclared` (credential exfiltration)\n- `CRED.ReadEnv` → `LLM.PromptOverride` (credentials leaked to a third-party LLM)\n- `EXE.RemoteFetch` → `FS.WriteStartup` (download then persist)\n\n---\n\n## 3. Interface Between Classification and Severity\n\n| Interface | Direction | Description |\n|-----------|-----------|-------------|\n| `C_base` | Classification → Severity | Capability baseline per Behavior node, default for `C` |\n| `required_dims` | Classification → Severity | Checklist of dimensions that must be evaluated |\n| `dataflow_role` | Classification → Severity | `source/transform/sink/none`, used by chain amplification |\n\nThe severity layer does not read the classification layer's prose descriptions or the `IntentMarker`; the classification layer does not read the final `Score`. The two layers can evolve independently.\n\n---\n\n## 4. Finding Data Structure\n\nA finding is one `(Behavior, evidence location)` hit. The evidence location is `(file path, line range, code snippet)`. The same Behavior hitting at multiple locations produces multiple findings; the same code hitting multiple Behaviors produces multiple findings; a `chain-finding` is itself a finding.\n\n```yaml\nfinding:\n  id: \"F-001\"\n  category:\n    surface: \"FS\"\n    behavior: \"FS.ReadSensitive\"\n    intent_marker: \"suspicious\"   # legitimate_elevated | suspicious | malicious_confirmed\n  evidence:\n    file: \"scripts/helper.sh\"\n    line_range: [23, 31]\n    snippet: \"...\"\n  scoring:\n    C: 4\n    R: 3\n    I: 1\n    B: 3\n    score: 36         # C × R × I × B = 4×3×1×3\n    tier: \"Low\"\n    badge: \"⚠️\"\n  dataflow_role: \"source\"\n  chain_id: null                  # fill with a chain id if this finding is part of a closed chain\n```\n\nAll fields are required (`chain_id` may be null). `score` must equal `C × R × I × B`; for `I = 0` findings, score is 0 and tier is always `Info`.\n\n---\n\n## 5. Audit Procedure\n\n### 5.1 Scan Scope\n\nThe audit target is the whole skill bundle, not `SKILL.md` alone. The scope has three layers:\n\n1. **Recursive enumeration of the skill directory.** Walk every file (including hidden ones) and classify by content rather than extension. Text-like content is analyzed as script/configuration; non-text content is judged by its location and reference relationships, without any fixed preset conclusion.\n2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.\n3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.\n\n### 5.2 Flow\n\n```\nInput: skill root directory\n  │\n  ▼\n[Step 1] Build scan inventory\n  ├─ 1a. Recursively enumerate files and classify by content\n  ├─ 1b. Parse references → add local files / register remote-URL findings\n  └─ 1c. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)\n  ▼\n[Step 2] Match each file against Behavior nodes → {category, evidence(file, line_range, snippet)}\n  ▼\n[Step 3] Score each finding independently: C ← C_base ± Δ; R/I/B per §2.2; compute Score; drop if R = 0\n  ▼\n[Step 4] Build a cross-file data-flow graph, detect closed chains → append chain-findings\n  ▼\n[Step 5] Emit all findings\n```\n\n### 5.3 Cross-File Reachability\n\n| File location | Default R |\n|---------------|-----------|\n| `SKILL.md` frontmatter + body | 3 |\n| Scripts explicitly refere\n\nArchive v0.1.2: 2 files, 7014 bytes\n\nFiles: Skill.md (16289b), _meta.json (142b)","readmeExcerpt":"Skill: Skill Auditor Owner: ambarion Summary: Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — SKI... Tags: latest:0.1.12 Version history: v0.1.12 | 2026-05-14T12:19:48.661Z | user Version 0.1.12 - SKILL.md description rewritten in English for improved clarity and accessibility. - No code or logic changes; core aud","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Score = C × R × I × B"},{"language":"text","snippet":"source → transform (any, optional) → sink"},{"language":"yaml","snippet":"finding:\n  id: \"F-001\"\n  category:\n    surface: \"FS\"\n    behavior: \"FS.ReadSensitive\"\n    intent_marker: \"suspicious\"   # legitimate_elevated | suspicious | malicious_confirmed\n  evidence:\n    file: \"scripts/helper.sh\"\n    line_range: [23, 31]\n    snippet: \"...\"\n  scoring:\n    C: 4\n    R: 3\n    I: 1\n    I_floor_applied: null         # null | \"T1\" | \"T2\" | … (which §2.2.1 trigger raised I, if any)\n    B: 3\n    score: 36                     # C × R × I × B = 4×3×1×3\n    arithmetic_tier: \"Medium\"     # tier from raw score\n    floor_rule_applied: null      # null | \"M1\"…\"M9\"\n    tier: \"Medium\"                # final = max(arithmetic_tier, floor_tier)\n    badge: \"⚠️\"\n  dataflow_role: \"source\"\n  chain_id: null                  # fill with a chain id if this finding is part of a closed chain"},{"language":"text","snippet":"Input: skill root directory\n  │\n  ▼\n[Step 1] Build scan inventory\n  ├─ 1a. Recursively enumerate files and classify by content\n  ├─ 1b. Parse references → add local files / register remote-URL findings\n  ├─ 1c. Match each outbound URL against §5.1.1 Untrusted-Sink Indicators\n  └─ 1d. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)\n  ▼\n[Step 2] Match each file against Behavior nodes → {category, evidence(file, line_range, snippet)}\n  ▼\n[Step 3] Score each finding:\n         3a. C ← C_base ± Δ; R / I / B per §2.2\n         3b. Apply §2.2.1 hard triggers → raise I to floor (record `I_floor_applied`)\n         3c. score = C × R × I × B; drop if R = 0\n         3d. arithmetic_tier ← §2.3\n  ▼\n[Step 4] Build cross-file data-flow graph (SKILL.md instructions count as source per §2.4)\n         → detect closed chains → append chain-findings\n  ▼\n[Step 5] Apply §2.5 Mandatory Confirmation Rules\n         per finding: tier ← max(arithmetic_tier, floor_tier); record `floor_rule_applied`\n  ▼\n[Step 6] Emit all findings"},{"language":"text","snippet":"Score = C × R × I × B"},{"language":"text","snippet":"source → transform (any, optional) → sink"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: skill-integrity-auditor\nversion: 0.1.12\nauthor: ambarion\ndescription: >-\n  Mandatory security audit for **every** Agent Skill that is newly added,\n  installed, imported, updated, or written. Scope of inspection: the full\n  bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,\n  etc.), and any bundled resource files. Audit dimensions cover skill\n  integrity, prompt injection, data exfiltration, persistence, cross-skill\n  writes, undeclared remote downloads, hardcoded credentials, and more.\n\n  ===== MUST BE TRIGGERED WHENEVER =====\n  * The user **adds / creates / installs / imports / updates / writes**\n    any single Skill.\n  * A skill is pulled into the agent's skills directory from ClawdHub,\n    GitHub, a URL, or a local folder.\n  * **Every** newly introduced or modified skill must be audited\n    **individually** — when N skills are added at once, emit a complete\n    report + the §7 final Chinese verdict line for each skill separately.\n    Sampling, merging, or single-summary output is not allowed.\n\n  ===== Triggering keywords (natural language, Chinese or English) =====\n  add skill, install skill, create skill, creating a new skill,\n  write a skill, scaffold a skill, new skill, register skill, import skill,\n  update skill, modify skill, bring in skill, hook up skill,\n  audit skill, scan skill, check skill safety, analyze skill, inspect skill,\n  verify skill, skill security, skill supply chain,\n  这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill,\n  添加 skill, 安装 skill, 创建 skill, 引入 skill, 更新 skill, 写一个 skill,\n  接入 skill。\n\n  ===== Do NOT trigger for =====\n  * General system health checks, project debugging, or normal development\n    work that does not touch any skill file.\n---\n\n# Skill Audit — Evaluation Core (Classification + Severity)\n\nThis file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).\n\n---\n\n## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE\n\nDetect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as \"当前输出语言为中文\", \"Detected language: English\", or similar meta-statements. Simply use the detected language silently for all subsequent output.\n\n| User message language | Output language |\n|-----------------------|-----------------|\n| Chinese | Chinese — entire output in Chinese |\n| English | English — entire output in English |\n| Other language | Match that language |\n| Cannot determine | Default to Chinese |\n\nAll intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7cw01r7ans9sdw59j32xy35h82sb79\",\n  \"slug\": \"skill-integrity-auditor\",\n  \"version\": \"0.1.12\",\n  \"publishedAt\": 1778761188661\n}"},{"path":"skill-card.md","content":"## Description:\n\nSkill Auditor guides security audits of newly added, installed, imported, updated, or written agent skills, covering integrity, prompt injection, data exfiltration, persistence, cross-skill writes, remote downloads, credentials, and related risks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[ambarion](https://clawhub.ai/user/ambarion)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to inspect an agent skill bundle and produce security findings plus a final verdict before installation, update, or release.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad file-reading scope can expose local files beyond the submitted skill bundle.\n\nMitigation: Run the skill only against a sandboxed, read-only copy of the target bundle and disable out-of-root reads unless explicitly approved.\n\nRisk: Remote fetching during audit can pull untrusted content into the review process.\n\nMitigation: Disable remote fetching by default and approve any static remote fetch per target before use.\n\nRisk: Broad triggers and strict final-output rules can interfere with unrelated skill workflows or structured responses.\n\nMitigation: Narrow activation triggers to explicit skill-audit requests and keep final-output formatting scoped to audit reports.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/ambarion/skills/skill-integrity-auditor)\n- [ClawHub publisher profile](https://clawhub.ai/user/ambarion)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Guidance]\n\n**Output Format:** [Markdown audit report with structured findings and a final Chinese verdict line]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Output language follows the triggering message for the report; the final verdict line is always Chinese.]\n\n## Skill Version(s):\n\n0.1.12 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — `SKI... Skill: Skill Auditor Owner: ambarion Summary: Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — SKI... Tags: latest:0.1.12 Version history: v0.1.12 | 2026-05-14T12:19:48.661Z | user Version 0.1.12 - SKILL.md description rewritten in English for improved clarity and accessibility. - No code or logic changes; core aud","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1432,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T04:03:24.712Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T04:03:24.712Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:43:48.578Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}