Back to skill

Security audit

deep-content-writer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a writing assistant, but it can steer publishable social content toward unsolicited follow or promotional prompts, including examples that reference the skill author's identity.

Review generated articles or posts carefully before publishing, especially the ending. Remove any follow request, account handle, creator attribution, or CTA that you did not explicitly provide. Also expect the skill to perform web research unless you tell your agent not to browse.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
tests/twitter.md:102
Finding

Persistent Third-Party Promotional Output Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states the skill activates automatically for very common writing requests such as articles, blog posts, newsletters, and threads. That broad trigger surface can cause the skill to engage in many routine prompts without clear user intent, increasing the chance of unintended behavior, style steering, or unnecessary processing of user-provided content. In this context the impact is limited because the skill is content-writing focused rather than privileged code execution or secret-handling, but it is still a real overreach issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger language is broad enough to match many generic writing requests, increasing the chance this skill is invoked in situations where a simpler or more appropriate skill should be used. Because this skill also mandates research and platform-specific shaping, over-triggering can indirectly expand data access and alter outputs beyond user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to perform web searches and gather external research before writing, which expands behavior from content drafting into autonomous information retrieval. That broader capability can cause unintended network access, privacy leakage through queried user topics, and reliance on untrusted external content without clear user consent or tool-gating.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes prescriptive locale-specific instructions such as using idioms/classics for Chinese audiences and referencing Chinese internet culture under the 知乎 section. Because this is presented as default platform behavior rather than an explicit user choice or opt-in, it can force a specific language/locale style in ways that may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The README highlights platform-specific adaptations including 知乎 and 头条 alongside other platforms, which suggests locale-specific output behavior. Because the description does not explicitly state that language or locale will be selected based on user preference, it may encourage a fixed locale/style assumption without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file is a markdown document, so SQP-3 applies. The content forces a specific language/locale for all users, and there is no indication that the skill is region-specific or that users can opt into Chinese, which matches the language/locale policy violation criterion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.