Back to skill

Security audit

Humanize Chinese 2.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is local and transparent, but it is deliberately built to make AI-written Chinese text less detectable.

Install only if you are comfortable with a tool whose core workflow can disguise AI-generated Chinese text and measure reduced detector scores. Use it for legitimate editing or authorized detector research, not to evade disclosure, academic integrity rules, platform moderation, or authenticity checks. Runtime behavior appears local and file-based, so review which input and output files you pass to the scripts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description directly encourages users to transform AI-written text so it becomes harder to identify as machine-generated, which meaningfully facilitates deceptive presentation. Because the project centers on detection avoidance rather than ordinary proofreading, the surrounding context makes the instruction more dangerous, particularly for fraud, spam, platform-rule evasion, and academic misconduct.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code accurately supports the detection-related parts of the description: Chinese text analysis, multiple detection categories, weighted 0–100 scoring, and sentence-level analysis are all present. However, the description also claims a second major capability—humanizing AI-generated Chinese text with seven style transforms, sentence restructuring, and context-aware replacement—which is entirely absent from this code chunk. The script is a detector CLI only; it does not rewrite, transform, or humanize text in any mode. There are no suspicious undeclared behaviors beyond normal file/stdin input and config loading, but the declared description materially overstates the implemented functionality, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s primary behavior is text rewriting/humanization, which partially matches the 'humanize' portion of the description. However, the description prominently claims AI-text detection capabilities with category-based scoring and sentence-level analysis, and none of that exists in the supplied code. There are no classifiers, heuristics producing scores, category outputs, or analysis reports. The code also exposes only five scene presets (general/social/tech/formal/chat), while the declared seven named styles are not implemented here; instead, an optional external script is invoked if present. This is a material description-behavior mismatch because major declared capabilities are absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description presents a dual-purpose tool centered on detecting AI-generated Chinese text and humanizing it, with substantial analytical features such as categories, weighting, and sentence-level scoring. The supplied code contains none of that detection or analysis logic. Instead, it is a standalone style-transfer script that transforms Chinese text into one of seven preset writing styles through regex-based cleanup, lexical substitution, random phrase insertion, emoji handling, and formatting changes. While the 7 style transforms mentioned in the description do exist, they are only one subset of the claimed functionality, and the primary advertised capability—AI-text detection with scoring and analysis—is absent. Therefore the declared purpose materially misrepresents the actual behavior.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly promises to make AI-generated Chinese text 'natural and undetectable,' which promotes concealment of machine-generated content without any guardrails, disclosure guidance, or misuse warning. In context, this is not a neutral editing claim: it frames the tool as helping users evade detection, increasing deception, authenticity, and moderation-evasion risks.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is explicitly positioned to make AI-generated Chinese text appear human-written, which enables evasion of AI-origin detection systems used for fraud screening, academic integrity, spam moderation, and platform policy enforcement. In this context, the 'humanization' framing is not neutral editing assistance; it is directly marketed as concealment of machine authorship.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

These instructions provide concrete rewriting methods—phrase replacement, restructuring, rhythm changes, vocabulary diversification, and colloquial injection—specifically to reduce AI-likelihood scores. That is operational guidance for defeating classifiers, making the skill more dangerous because it offers a repeatable transformation pipeline rather than generic writing advice.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow explicitly instructs users to detect, rewrite, and then verify score reduction, creating a closed-loop process for testing and refining successful AI-detection evasion. This materially increases abuse potential because it turns the skill into a measurable optimization system for bypassing institutional or platform safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The prompts and expected behaviors are entirely constrained to Chinese-specific processing and styles, including running language-specific scripts like detect_cn.py, humanize_cn.py, and style_cn.py. Because this file contains no documented opt-in or justification for enforcing a specific language/locale, it presents a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The package description explicitly scopes the skill to processing Chinese text only, but this manifest does not indicate that the language limitation is optional, user-selected, or otherwise justified as a region- or language-specific tool. Under the policy, a forced language/locale constraint in natural-language metadata can be a violation unless it is clearly documented and justified.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/compare_cn.py (reported line 23)May include surrounding context.

python
cmd.append('-j')
    
    try:
        result = subprocess.run(
            cmd, input=text, capture_output=True,
            text=True, encoding='utf-8', timeout=30
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/compare_cn.py (reported line 43)May include surrounding context.

python
cmd.append('-j')
    
    try:
        result = subprocess.run(
            cmd, input=text, capture_output=True,
            text=True, encoding='utf-8', timeout=30
        )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code defines the skill as a Chinese-only analysis tool and presents all user-facing descriptions in Chinese, with no option to select another language or explicitly opt into the locale restriction. That is a natural-language locale policy concern under the rule because the skill forces a specific language rather than offering a user choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file description and implementation explicitly limit the detector to Chinese text, and the code only analyzes Chinese characters and Chinese-language patterns. Under the stated policy, forcing a specific language/locale without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring explicitly defines the tool as transforming Chinese text, and the implementation throughout uses Chinese-specific assumptions and messages. This is a natural-language locale constraint with no user opt-in or alternate language choice documented in the file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill that can detect AI-generated Chinese text with 20+ categories, 0-100 weighted scoring, and sentence-level analysis. In this file, the implemented behavior is a humanization pipeline plus optional style transformation; there is no classifier, category analysis, scoring output, or sentence-level detection results anywhere in the code path.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

For a pure-Python local text humanizer, launching an external Python process is not an obvious requirement of the stated purpose, especially when the manifest emphasizes a self-contained implementation. The code invokes style_cn.py through subprocess rather than performing the transformation in-process.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/humanize_cn.py (reported line 495)May include surrounding context.

python
tmp_path = tmp.name
            
            try:
                proc = subprocess.run(
                    ['python3', style_script, tmp_path, '--style', args.style],
                    capture_output=True, text=True, encoding='utf-8'
                )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON file defines detection and replacement rules entirely around Chinese phrases and regexes, indicating the skill behavior is constrained to a specific language/locale. Because the file does not document an explicit Chinese-only scope or user opt-in, it can violate the language/locale policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring states the tool transforms text into Chinese writing styles, and all supported styles and descriptions are presented only for Chinese usage. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified or alternatives are offered.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest specifically claims seven style transforms such as casual, zhihu, xiaohongshu, wechat, academic, literary, and weibo. This file defines only five internal scene configurations (general, social, tech, formal, chat), and the documented style option merely shells out to another script rather than implementing the claimed transforms here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The argparse description, help text, and runtime messages are all presented only in Chinese, with no option for users to select another language. This is a natural-language locale constraint that is not justified in the file and does not provide user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.