Back to skill

Security audit

Paper DeepRead Comic Studio

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed paper-reading and storyboard workflow, but it needs Review because its local bundle-building helpers can package more workspace data than intended, including files reached through symlinks, before upload or sharing.

Install only if you are comfortable with a Chinese-first paper workflow that writes local workflow metadata and bundles project files. Before running the bundle builders, use a dedicated clean workspace, remove symlinks and unrelated files, keep the output ZIP outside the input tree, and inspect the ZIP before uploading or sharing it. Do not place credentials, private keys, or unrelated sensitive documents in the workspace.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_paper_deep_reading_bundle.py:293
Finding

Recursive archive creation can disclose files referenced by symbolic links

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 662)May include surrounding context.

md
| Author Defender | rebuttal and best-paper pitch | strongest acceptance argument and weakest vulnerable claim |
| Teacher | whether a non-specialist can follow | analogy, prerequisite list, teachback questions |

### Talk / PPT blueprint rule

Do not create a separate final report that competes with the authoritative detailed report. If a talk or slide blueprint is needed, make it a derivative artifact that cites the authoritative report as its source.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README hard-codes Chinese-language resume prompts without indicating that the user may choose another language, which can cause the agent to privilege embedded prompt text over the user's language preference. While not directly enabling code execution, this can create prompt-routing ambiguity and reduce user control, especially in multilingual environments where exact trigger wording affects behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The resume trigger phrase is generic enough that ordinary user text could accidentally invoke the skill's resumptive behavior, causing the agent to continue prior workflow state when the user may have intended a fresh request. In an agent setting, broad trigger phrases increase prompt-collision risk and can lead to unintended execution paths or disclosure of intermediate workflow state.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares executable capabilities such as file read/write and shell-related workflows but does not define an explicit tool-scope boundary. In an agent environment, this can lead to overbroad authority, making it easier for later prompts or chained instructions to trigger filesystem modification, packaging, or script execution beyond what users expect from a paper-reading skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown repeatedly instructs users to resume or invoke the skill using Chinese-only prompt templates such as '使用这个skill,根据状态...'. Because these are framed as required reminder text and restart-safe commands, the skill imposes a specific language/locale convention without documenting user choice or an explicit justification for restricting prompts to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed example user inputs are exclusively in Chinese, which imposes a specific language expectation in the manifest without any opt-in or documented locale constraint. This is a natural-language policy issue because the skill does not indicate that other languages are supported or that Chinese is required for a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown contract repeatedly requires _detailed_cn report outputs and uses Chinese-titled mandatory sections, which imposes a specific language/locale on skill behavior. The file does not provide an opt-in, alternative language path, or a documented reason that the skill must be Chinese-only, matching the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema includes authoritative report patterns ending in _detailed_cn.md and extensively mandates Chinese section headings throughout the required and mandatory sections. That constitutes a natural-language locale constraint embedded in config values, but the file does not indicate user opt-in, multilingual alternatives, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed output layout repeatedly requires _cn filenames such as <paper-slug>_detailed_cn.md, teaching_outline_cn.md, and other Chinese-designated artifacts. This imposes a specific language/locale in the skill specification, and the file does not indicate user choice, opt-in, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing instructions are written entirely in Chinese and require a specific reply phrase, which imposes a language choice without offering an alternative or opt-in. This is a natural-language policy issue because it constrains the interaction locale regardless of user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The output policy hard-codes _cn teaching artifacts and earlier guidance mixes Chinese into the required teaching format, which implies a specific language/locale requirement. The file does not offer a user choice of language or explain why Chinese-only outputs are required, so this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/init_paper_deep_reading_scaffold.py (reported line 65)May include surrounding context.

python
def refresh_project_directory_index(workspace_root: Path) -> None:
    script_path = Path(__file__).resolve().parents[1] / "scripts" / "update_project_directory_index.py"
    subprocess.run(
        [
            sys.executable,
            str(script_path),

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scaffold template begins with Chinese headings such as 详细精读, and later embeds Chinese-only suggested user inputs for the next stage. Because the file provides no alternative language path or user-selectable locale, it imposes a specific language on downstream use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated report filename is hard-coded to _detailed_cn.md, and the report stub content is written in Chinese, indicating the skill expects Chinese output by default. This is reinforced elsewhere in the file by Chinese-only next-step prompts, with no visible mechanism for the user to select another language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This script recursively enumerates the entire workspace, classifies every file and directory, and writes inventory artifacts describing the project structure. The manifest describes a skill for deep-reading papers and producing source-grounded teaching/comic-storyboard outputs; maintaining a generic project directory index is an internal workspace-management capability that is not part of that stated end-user purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest emphasizes understanding research papers and producing teaching reports plus storyboard workflows, but the executed behavior here is to scan a workspace and generate JSON/Markdown directory indexes. That behavior is materially different from the described user-facing functionality and goes beyond an obvious implementation detail of paper comprehension or storyboard preparation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a skill for deep-reading papers and producing grounded teaching reports and comic-storyboard workflows. This script instead creates directories and updates a generic routing/status JSON file, which is orchestration/state-management infrastructure rather than a direct capability needed for paper understanding or storyboard preparation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow hard-codes a Chinese-language user-facing reminder (如果开启新会话...) without offering a language choice or adapting to the user's language. This can cause user confusion, reduce accessibility, and create misleading or unusable guidance for non-Chinese-speaking users, especially because the text is framed as a required status-turn instruction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.