Back to skill

Security audit

Research Paper Figure Skill Factory

Security checks for vulnerabilities and agentic risk

Overview

The skill is a transparent research-figure workflow, with expected local corpus creation and image-generation steps, but no hidden execution, credential use, persistence hooks, or destructive behavior found.

Install only if you are comfortable with a workflow that can read provided/local paper material, retrieve lawful open-access PDFs, create local corpus and generated-skill files, and send prompts or reference-image context to approved image-generation tools. Non-Chinese users should be aware that many templates force Chinese headings and follow-up prompts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (32)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates Chinese headings and prescribed next-prompt text for every text reply without checking user language preference or providing a justified locale requirement. This can override user intent, degrade usability, and create prompt-routing or downstream integration failures in systems expecting the conversation language to remain consistent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
- `SKILL.md`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description is written entirely in Chinese and provides no indication that users may interact in other languages or choose a preferred locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicit and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation description is broad enough to trigger on many generic requests about research-paper figures, which can cause inappropriate routing to this highly prescriptive factory skill instead of a narrower or safer tool. Over-broad invocation increases the chance of unexpected behavior, unnecessary processing, and user confusion, especially because this skill imposes rigid workflow and modality constraints once activated.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- the workflow lacks a dedicated `IMAGE_ONLY` candidate-board step before direction lock;
- examples show text candidates followed directly by final prompt or final image generation;
- the state footer cannot record `visual_candidate_board_status`, `candidate_image_batch_id`, and `selected_visual_candidate`;
- multi-option next prompts do not ask the user to generate/display multiple candidate images or schematic candidates, normally 6.

### Strict Text/Image Separation

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hard-codes Chinese-only output elements and a required Chinese follow-up prompt regardless of the user's language or accessibility needs. This can override user intent, reduce transparency, and create prompt-control behavior that makes downstream agents less predictable or less usable, especially in multilingual or policy-constrained environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example content is predominantly in Chinese and presents the workflow/output format that the skill is expected to follow, without offering a language-selection mechanism or documenting why Chinese is required. In a general-purpose research skill, this can cause unintended language coercion, reducing usability, obscuring safety-critical instructions for users who do not read Chinese, and increasing the chance of operator error during evidence review or figure-generation workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing operational instructions and example prompts in Chinese, but does not indicate that the language is optional or user-selectable. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the host to create directories/files under /mnt/data and to search for and download PDFs, but it does not require clear user consent or a user-facing warning before network access and disk writes occur. In an agent setting, silent filesystem and network actions can lead to unexpected data persistence, bandwidth usage, or policy violations, especially if the host has broader access than the user realizes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing operational instructions almost entirely in Chinese, including execution guidance and suggested prompts. Under the policy for natural-language violations, forcing a specific language without user opt-in should be flagged unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is predominantly in Chinese and presents operational instructions and prompts without offering a language choice or opt-in. This can exclude or mislead users who do not understand Chinese, causing them to approve workflows, state transitions, or content-generation steps they cannot adequately review, which is a meaningful safety and usability risk in an agent skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section headers and operating instructions switch into Chinese for core execution guidance, and the suggested invocation examples are also only in Chinese. This imposes a language/locale constraint in the skill content without any opt-in, alternative language path, or stated region-specific reason.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest embeds broad invocation-style prompt templates that can steer downstream agent behavior without clear trigger constraints, exclusions, or user-intent checks. In a meta-skill that generates and drives other skills, this increases the risk of over-broad activation, prompt injection surface expansion, and unintended execution paths across unrelated contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest hard-codes Chinese-language prompt prefixes and fallback prompts without language negotiation or locale justification. This can cause user confusion, misexecution, or hidden instruction routing when the user or host environment operates in another language, especially because these strings are framed as operational prompts to be copied into future turns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The starter prompts are all written in Chinese and implicitly steer interaction into Chinese without presenting any language choice or documenting a requirement for Chinese-only operation. This can exclude users, cause misunderstanding of safety-critical instructions, and create inconsistent behavior if downstream users assume the skill supports the workspace default language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The section titled 'Required Chinese Reminder' requires generated skills to include a reminder in Chinese, and the quoted text is entirely Chinese. This imposes a specific language requirement without indicating user choice, opt-in, or a justified locale-specific scope, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The block quote provides the user-facing reference prompt entirely in Chinese, and the file does not indicate that language choice is optional or limited to a China-specific workflow. This creates a natural-language locale policy issue because it implicitly fixes a specific language without offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The contract hard-requires Chinese section headings and reply structure for every text response, without any user-language negotiation or locale fallback. This can cause unsafe or unusable behavior in multilingual contexts by forcing outputs the user may not understand, increasing the chance of consent failures, mis-execution of instructions, and inaccessible workflow state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The required next-turn prompts are prescribed in Chinese-only wording and are the only copyable prompts allowed, which constrains user interaction to a single language regardless of context. In a workflow-heavy skill, this raises the risk of user confusion, accidental confirmations, and broken continuity when users cannot reliably understand or reuse the mandated prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template hard-codes Chinese-language prompt text for the minimal request, which can override or pressure the user into a language they did not choose. This creates a prompt-quality and accessibility issue, and may cause misunderstanding or exclusion for users expecting locale neutrality, but it does not directly enable code execution, data exfiltration, or privilege abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The follow-up example again mandates Chinese-language wording without user opt-in, reinforcing a non-consensual language switch in ongoing interaction. In this figure-generation skill, that mainly risks user confusion, lower usability, and accidental mishandling of requirements rather than a direct security compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The rubric hard-codes a Chinese-language diagnostic template without any user opt-in, locale detection, or documented reason. This can cause unauthorized language switching, degrade usability, and create prompt-behavior misalignment where outputs are less understandable, less reviewable, or inconsistent with user expectations and surrounding English-language workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The schema hard-codes use of an exact Chinese prompt prefix and fallback prompt from another file without any user-locale negotiation or justification. This can cause deceptive or confusing interactions, reduce user awareness of what the agent is asking, and create opportunities for prompt-routing or consent issues when users do not understand the enforced language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file requires specific Chinese-only output sections (当前状态与产物, 下一步你可以这样问) and a fixed Chinese prompt without providing any user-language negotiation. This can degrade usability, cause instruction-following failures for non-Chinese users, and create confusing or inaccessible outputs in multilingual contexts, though it is not a direct code-execution or data-exfiltration issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file prescribes exact user-facing wording in Chinese: "请回复‘生成 6 张候选图’" as the recommended next-step prompt. Because this is framed as required policy text and no alternative language or opt-in is offered, it can force a specific language/locale on users, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.