Back to skill

Security audit

Video Script Writer

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese short-video script-writing skill made of Markdown guidance files, with no code execution, network access, credential handling, or persistence.

Install this if you want Chinese-language short-video script help. Be aware that it is intentionally Chinese-focused and has broad triggers around script and content-creation wording, so disable it or ask explicitly if you need general writing help or another language.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description states the skill is a '中文短视频脚本写作助手', which frames the skill as operating in Chinese only. The README does not indicate that users can choose another language or that the Chinese-only scope is a justified region-specific requirement, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s activation criteria are broad and keyword-driven, covering common terms like '脚本', '教程类内容创作', and generic content-creation scenarios. This can cause unintended invocation in unrelated conversations, leading the agent to apply domain-specific behavior when the user did not request it, which is a real scope-control weakness even if not directly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Mandating Chinese-only output without checking user preference or locale can override user intent and create unsafe or unusable responses for non-Chinese readers. In multi-user or multilingual environments, hardcoded language constraints are a genuine quality and control issue because they can cause the agent to disregard explicit user needs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is entirely written as prescriptive guidance in Chinese and repeatedly uses mandatory language such as “脚本必须做平台级适配,” but does not offer any user language or locale choice. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a reportable locale/language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown test file presents all instructions, inputs, and expected outputs exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrase for generating a script from a topic is phrased in ordinary conversational language and may match many harmless requests that are not actually asking to invoke this skill. Overbroad natural-language triggers increase the chance of accidental routing and reduce predictability of agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The additional mode trigger relies on generic phrasing like asking for openings on a topic, which may overlap with normal writing help outside the intended short-video context. This makes misrouting plausible and can cause the agent to inject short-video assumptions into broader content tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The optimization-mode trigger accepts 'give me an existing script' without clearly limiting what kinds of scripts are in scope. That can pull in unrelated or sensitive text for analysis under the wrong skill, creating unnecessary processing and possible contextual leakage across tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The long-content conversion trigger is broad enough to capture generic summarization, editing, or transformation requests that are not intended for this skill. This can lead to accidental invocation and content reshaping in a specialized format the user did not ask for.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown content presents all instructions, labels, and examples only in Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in can be a natural-language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.