Back to skill

Security audit

AI Combat Shot Prompts

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only combat prompt-writing skill with disclosed violent cinematic content and no code, persistence, credentials, or hidden data access.

Install only if you want a Chinese wuxia/xianxia combat prompt guide. When using it, ask the agent for non-graphic or choreography-focused outputs if you do not want blood, injury close-ups, or intense violence.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is explicitly designed to generate combat prompts with injury-focused details such as blades cutting toward the neck, flesh impact, and "刀刃入肉" close-ups, but it provides no safety warning, moderation guidance, or constraints on graphic gore. In context, this increases the likelihood that a downstream agent will produce violent or graphic content by default, including escalations from generic fighting requests into more explicit bodily harm descriptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is framed as Chinese wuxia/xianxia-oriented and says its core ability is to write prompts in that context, which can unnecessarily constrain output language, cultural framing, and style if the user did not ask for that. While not a classic security flaw, it can cause misalignment, exclusion, or unexpected behavior in multi-locale systems by overriding user preference and narrowing content generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill content is written in Chinese and presents its guidance solely in that language, with no indication that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the policy for natural-language violations, a skill that effectively forces a specific language without opt-in should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

在“平台适配”部分,内容明确规定了不同平台的语言偏好,如“中文为主”“中文描述”以及“英文稳定”。这构成了语言/locale 约束,但文档没有说明这是可选建议,也没有提供用户语言偏好或 opt-in 机制,因此符合自然语言策略中关于强制特定语言的风险点。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.