Back to skill

Security audit

book-breakdown

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed offline workflow for turning a user-provided ebook into local summary files and a single HTML report.

Install this only if you want an offline, Chinese-oriented book breakdown workflow that writes a project folder containing the original ebook copy, extracted chapter text, summaries, metadata, and a final HTML report. Review where the agent will create that folder, especially for copyrighted or private books.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions are very broad: they activate not only on explicit 'book breakdown' requests, but also on general intents like '总结这本书' or 'book summary'. In an agent setting, this can cause over-triggering, pulling large local files into a heavyweight workflow and generating persistent disk artifacts when the user may have only wanted a lightweight answer, increasing privacy and unintended file-processing risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example metadata schema fixes both source_language and output_language to zh-CN, and the document does not offer users a language/locale choice for the generated deliverables. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly justified and documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and the entire instruction file are written as mandatory Chinese-language operational guidance, and there is no indication that the user can opt into another language or locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless it is clearly documented as region-specific or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title "HTML 输出规范" and the entire instruction set are written as a mandatory output specification in Chinese, with no indication that users may select another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.