Back to skill

Security audit

Writing Style Cloner - 个人写作风格克隆器

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only Chinese writing-style rewriting skill with no code execution, persistence, credential access, or hidden data movement, though its broad triggers could affect ordinary writing requests.

Install this only if you want Chinese draft or transcript rewriting in Antonia's personal style and you have appropriate rights or consent to use that style. Consider narrowing the trigger phrases so generic requests like writing an article or converting speech to prose do not automatically impose this specific voice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The primary skill description is written as a Chinese-only writing-style cloner for producing articles in Antonia's style, and the README does not indicate that users may choose another language or locale. Under the stated policy, a skill that imposes a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger set includes generic phrases like '帮我写文章', '写成文章', and '口语转书面', which overlap heavily with common assistant tasks. In context, this is more dangerous because the skill contains a large, prescriptive persona/style payload; ambiguous routing could silently steer broad user requests into unauthorized imitation or content shaping not requested by the user.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keyword at line 6 is broad enough to match many ordinary writing requests, which can cause the skill to activate outside its intended niche. That creates prompt-scope hijacking risk: users asking for generic writing help may unknowingly invoke a style-cloning skill that imposes hidden behavioral instructions and unnecessary transformation of user content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file establishes transformation rules exclusively in Chinese and directs use of a specific style profile, but does not indicate that the language choice is optional or limited to Chinese-language workflows. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.