Back to skill

Security audit

humanizer-cn

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese text-rewriting skill with no hidden execution, network access, persistence, or credential handling in the inspected artifacts.

Install this if you want a Chinese-focused rewriting assistant. Use explicit prompts or delimited text blocks when invoking it, especially if you only want analysis rather than automatic rewriting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README allows invocation not only via the explicit /humanizer-cn command but also by asking users to 'paste text and state your intent directly'. That broad trigger can cause the skill to activate in loosely matched conversational contexts, increasing the chance of unintended prompt interception or modification of unrelated Chinese text during normal chats.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description says the skill is specifically for identifying and removing AI-writing markers from Chinese text, which imposes a language constraint. In this file, the skill does not state that users can choose another language or that the Chinese-only behavior is an explicit opt-in, creating a potential language/locale policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users they can invoke the skill with a broad natural-language phrase (“去除 AI 痕迹”), which increases the chance of accidental or overly eager activation in unrelated contexts. In agent environments, ambiguous triggers can cause unintended transformation of user text, including rewriting content the user did not clearly consent to modify.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.