Most static findings are false positives from JavaScript examples, Markdown backticks, _id or uid identifiers, and Object.keys usage. I confirmed the SKILL.md raw fallback URLs and parent-directory sibling references because they can load mutable or out-of-scope instructions at runtime. No prompt injection phrases were found in the reviewed files.
SKILL.md directs agents to use published fallback URLs for sibling skills when local references are absent. This can load mutable external instructions outside the audited package.
The instructions explicitly point agents to raw remote SKILL.md files as fallback sources. This is not exfiltration, but it materially expands the instruction trust boundary.
Capability review items (8)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te
The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.
- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool
The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.
- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co
The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.
- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
Most static findings are false positives from JavaScript examples, Markdown backticks, _id or uid identifiers, and Object.keys usage. I confirmed the SKILL.md raw fallback URLs and parent-directory sibling references because they can load mutable or out-of-scope instructions at runtime. No prompt injection phrases were found in the reviewed files.
SKILL.md directs agents to use published fallback URLs for sibling skills when local references are absent. This can load mutable external instructions outside the audited package.
The instructions explicitly point agents to raw remote SKILL.md files as fallback sources. This is not exfiltration, but it materially expands the instruction trust boundary.
Capability review items (8)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te
The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.
- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool
The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.
- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co
The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.
- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.
- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co
The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.