Back to skill

Security audit

室内设计师小红书文案助手

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese Xiaohongshu copywriting helper for interior designers, with no evidence of hidden access, persistence, data theft, or destructive behavior.

Install this if you want Chinese-language Xiaohongshu marketing copy for interior-design content. Be aware that the generic “内容策划” trigger may activate it for broader content-planning requests, and review generated marketing copy before publishing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase “内容策划” is very broad and can match many ordinary user requests unrelated to this specific skill, causing unintended invocation. Overly generic triggers increase the attack surface for prompt-routing mistakes, user confusion, and accidental activation in unrelated contexts, though this is not inherently malicious in this marketing-content skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and prompt template are entirely in Chinese and instruct the model to generate Xiaohongshu copy in that language/style, but the skill never offers a language or locale choice. This is a natural-language policy concern because it imposes a specific language by default rather than making it opt-in or clearly documenting a justified regional restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language instructions, examples, and interface cues all assume Chinese usage, which can be interpreted as forcing a specific language without explicitly offering a user choice. Under the policy, language constraints should either be optional or clearly documented as a justified locale-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill name and description are entirely in Chinese and describe a copywriting assistant specifically for Xiaohongshu content, with no indication that users can choose another language or locale. This can conflict with language/locale policy expectations when a skill implicitly constrains interaction to a specific language without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.