Back to skill

Security audit

Academic Results Writer

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed academic-writing skill for Results sections, with local long-output file writing as its main operational caution.

Install only if you are comfortable with a Chinese-default academic Results-writing workflow and with long outputs being saved as local Markdown files on your Desktop. Review generated statistics carefully, especially examples or revisions that might infer missing values, and choose English output explicitly when needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (26)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains natural-language statements that the README and SKILL.md were fully localized to Chinese. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation, and no opt-in or region-specific justification is given here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The invocation guidance says to activate when the user asks to write Results, revise a draft, convert tables/figures, audit Results, or adapt style, but it provides no explicit exclusion conditions or boundaries for when similar general writing requests should not invoke this skill. Phrases like revising a draft or checking whether a Results section has problems are broad enough to overlap with ordinary academic editing requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file includes mandatory example/output language in Chinese, such as instructions that the model 'must NOT write' one Chinese phrase and 'write' another Chinese sentence when conditions are met. This imposes a specific output language without indicating user choice or opt-in, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown sets a default of "APA-like Chinese format" when the user has not specified a journal or language preference. That is a natural-language policy concern because it forces a locale/language-specific output convention without explicit user opt-in, while the policy allows such constraints only when the user is given a choice or the limitation is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents required output wording in Chinese alongside English glosses, including hard-fail checks tied to those phrases. Because the guardrails prescribe a specific language/locale style without stating that the user can choose language or that the skill is limited to a Chinese-language workflow, this may violate the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The revision-mode spec hard-codes a Chinese output template (e.g., section headers and example output) without an explicit user-consent or language-negotiation step. In isolation this is not a classic security flaw, but it can cause instruction-priority issues where the agent ignores a user's requested language or locale, leading to unintended disclosure, workflow breakage, or unsafe misunderstanding in downstream use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The target-paper mode section references required output sections only in Chinese, and elsewhere the file repeatedly prescribes Chinese phrasing alongside English alternatives without stating that the user may choose the language. This can amount to a language-policy violation because it may force a specific output language absent user opt-in or a documented locale justification.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains prescribed reporting templates in Chinese, and several sections provide only Chinese wording rather than explicitly offering a language choice. That can amount to a language/locale policy issue because the skill appears to steer output language without documented user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction requires the first occurrence of variables to use a Chinese name with the English original, and subsequent occurrences to use Chinese only. This imposes a specific language/locale behavior without offering the user a choice or documenting an opt-in, which matches the policy-violation category for language constraints.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains a natural-language locale policy constraint: 'Default style' is explicitly Chinese academic writing convention. Under the policy, forcing a specific language or locale without user opt-in is reportable unless the constraint is clearly optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example invocation and expected output are written in Chinese and instruct the model in Chinese, with no indication that users may choose another language. This creates a natural-language policy concern because the skill appears to impose a specific language/locale without user opt-in or documented necessity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example instructs writing output to a concrete path under the user's Desktop without any warning, confirmation, or overwrite safeguards. In an agent skill, this can normalize silent filesystem writes and lead to accidental data exposure, clobbering of existing files, or unexpected persistence of sensitive research content on disk.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented purpose is confined to generating and adapting academic Results content, yet L035 states that long outputs automatically switch to a file output mode under ~/Desktop/OpenClaw_Paper_Analysis/outputs_md/results_writer/. Writing files is broader than the manifest's described text-generation behavior and is not presented as part of the skill's core scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example prompt explicitly states '默认中文', which sets a specific language default for the skill. Under the policy, forcing a language or locale without user opt-in can be a natural-language policy violation unless the skill offers a clear choice or justified regional constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The phrase 'Auto-activates when output is long' combined with several loosely defined conditions like 'previous truncation' or 'design-incompatible fallback' lacks clear thresholds and may cause unintended behavior. This is a markdown-defined activation condition, so ambiguity in when the mode does or does not activate falls under vague triggers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction mandates a specific Chinese warning sentence: "Write: ...". This forces a language choice in natural-language behavior without indicating user opt-in or that the skill is intentionally limited to Chinese-language workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L47 uses the Chinese phrase "显著提高/显著降低" inside an otherwise English checklist. This introduces a language-specific requirement without any visible opt-in, multilingual alternative, or stated justification that the skill is intended only for Chinese-language output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown example presents the expected output entirely in Chinese while the surrounding file is in English, which effectively steers the skill toward a specific language/locale. The file does not indicate that Chinese output is optional, user-selected, or required for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example input and expected output are entirely in Chinese, and the file does not indicate that language selection is optional or user-driven. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown example presents the user input and expected output in Chinese, which can imply the skill operates in a fixed language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.