Back to skill

Security audit

AI Video Shot Sequence

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Chinese-language skill for designing AI video shot sequences, with no executable behavior or hidden system access found.

Install this if you want Chinese-language guidance for building cinematic shot sequences. Be aware that the framework has a minor element-count inconsistency and does not provide bilingual instructions, but it does not appear to run code, access accounts, persist state, or modify files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest-style description and trigger guidance are presented only in Chinese, which effectively forces a specific language for activation and use. The file does not offer multilingual support, user opt-in, or a documented reason that this skill is intentionally region- or language-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill reference is written in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file contains instructional content exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may opt into another language. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L233-L246 introduce an eighth, ninth, and tenth element on top of the original seven-element framework, which totals ten elements. However, L248 states that each shot should be described under a '九要素框架' (nine-element framework). This is an internal documentation contradiction about the skill's intended framework.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.