Back to skill

Security audit

RedNote Writer Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese Xiaohongshu copywriting skill with no code execution, credential access, persistence, or hidden system behavior.

Install this if you want Chinese Xiaohongshu-style marketing copy. Users who need other languages or non-Xiaohongshu formats should confirm that separately, but the artifact does not show security-sensitive behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill name, description, examples, and output instructions are entirely framed around generating 小红书 content in Chinese, with no indication that users may choose another language or that the Chinese-only scope is an explicit opt-in. This is a natural-language locale constraint that can violate policy when a specific language is imposed without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description string "小红书爆款文案生成器" indicates the skill is specifically for generating Xiaohongshu copy in Chinese, but the manifest does not mention any user choice or opt-in for language/locale. This is a natural-language locale constraint that may violate language-choice policy when not explicitly offered as optional or justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.