Back to skill

Security audit

小红书标题策略

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Xiaohongshu title-writing helper with no code execution, credential access, persistence, or hidden data handling.

Install this if you want Chinese Xiaohongshu title strategy with traceable formula IDs. If you need another language, bilingual output, or a non-Xiaohongshu format, tell the agent explicitly because the skill defaults to Chinese platform-specific titles.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill sets a default behavior to 'write in Chinese' unless the user says otherwise, which can override user or system expectations in multilingual environments and cause unintended language output. While this is not directly a security exploit, it is a policy/quality issue that can lead to unsafe assumptions, reduced transparency, or prompt-routing mistakes when downstream components expect explicit user consent for language selection.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The default prompt hard-codes Chinese Xiaohongshu title generation without any indication that the user can choose another language or explicitly opt in. This can override user expectations or broader agent context, causing unwanted language-constrained output and reducing user control, though it does not by itself create a direct code-execution or data-exfiltration risk.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The entire template is written in Chinese and labels the output structure specifically for a Chinese-language title package, with no indication that users may choose another language or locale. This creates a natural-language policy concern because it imposes a language choice by default rather than offering user opt-in or documenting a justified regional limitation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The title and description explicitly frame the catalog as Chinese-only content for Xiaohongshu, and there is no indication that users may opt into another language or locale. Under the policy rule, forcing a specific language without user choice is a natural-language locale constraint that should be documented or made optional.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The entire guidance is written exclusively in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-language context. Under the policy, a language or locale constraint should be optional or clearly justified to avoid imposing a specific language by default.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file specifies the workflow exclusively in Chinese, which can amount to a language policy violation if users are not given an explicit language or locale choice. The document does not indicate that the skill is intended only for Chinese-speaking users or a China-specific workflow, nor does it offer opt-in or alternatives.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This markdown file contains natural-language guidance only in Chinese, and there is no indication that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Static analysis

No suspicious patterns detected.