Back to skill

Security audit

Text-to-Comic · 文字转漫画

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent comic-generation workflow that uses packaged style, schema, and character assets with no evidence of hidden execution or data theft.

Reasonable to install for visual storytelling. Be aware that generated storyboards, prompts, images, and optional custom character cards may be saved locally, so avoid using private photos or sensitive personal material unless you are comfortable with those local artifacts and image-generation processing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
- `characters/protagonist-ref.png` is an optional reference sheet; use it only when the host image tool accepts reference images, otherwise rely on the text anc

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The Chinese section states that stable in-image text should use English, which imposes a language choice as a hard constraint rather than offering it as an option. This is a natural-language policy concern because it steers output language behavior without explicit user opt-in or a user-selectable alternative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says to use short English text inside images when generation reliability matters, while Chinese captions and narration are overlaid during assembly. Even if justified by model reliability, this is written as a standing rule rather than a user choice or explicit opt-in, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly instructs the agent to read local files such as characters/protagonist.md, presets/styles.json, schema files, and examples, which implies file-read capability, but it does not declare a constrained tool scope via permissions or allowed-tools. That mismatch can let the runtime grant broader file access than the skill actually needs, increasing the blast radius if prompt injection, path confusion, or implementation mistakes cause unintended reads.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown skill description says the old experience should apply if the user "simply says "画成漫画" or gives a short story," which is a broad activation condition likely to overlap with ordinary conversation. The file does not pair this with negative trigger examples or a narrower invocation context, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions say to add Chinese captions, narration, or labels during assembly when possible, which imposes a specific language choice. Because this default is not presented as user-selectable or justified as a region-specific tool, it conflicts with the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest sets the top-level language to "zh-CN", and the panel dialogue entries also consistently enforce the same locale. Because the file provides no opt-in, alternative locale handling, or justification that this is a region-specific skill, it appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest sets "language": "zh-CN", which imposes a specific language/locale in natural-language configuration. The file does not indicate that this is user-selectable or that the skill is explicitly intended as a China-specific or Chinese-only experience, so it may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains natural-language guidance to always publish with a fixed Chinese-inclusive name: "always publish with --name "Text-to-Comic · 文字转漫画"." That is a locale/language constraint stated as mandatory rather than optional, and the text does not present it as a user opt-in choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The entire skill file is written in Chinese and defines the default protagonist card only in that locale, with no indication that users may choose another language or that the skill is intended exclusively for Chinese-speaking contexts. Under the policy rule for language/locale, this can be a natural-language policy concern when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON specifies "language": "zh-CN", and the dialogue entries also repeat the same locale, which forces output into a specific language/locale. Under the policy rule, locale restrictions should either be optional for the user or clearly justified as region-specific; this file does neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This manifest/config file contains natural-language fields such as legacy_name_zh that enforce a specific locale in the skill data model. Because the file does not document that Chinese labels are optional, locale-specific, or user-selectable, it may conflict with a policy requiring language choice or justification for locale constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a manifest/config-type file, so vague-trigger/style policy checks apply. The unrestricted "language" string does not specify allowed values, default behavior, or exclusions, which creates ambiguity around what language inputs are valid and how the skill should behave across locales.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.