Back to skill

Security audit

预告片导演

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language prompt-writing skill for cinematic image prompts, with no code execution, data access, network use, or persistence.

Install this if you want a Chinese workflow that formats ideas into cinematic image-generation prompts. Expect it to ask clarifying questions first, use fixed film-style parameters, and include some English style tags; there is no evidence that it accesses files, credentials, the network, or persistent system settings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases include broad terms like “预告片风格”, “电影级prompt”, and especially “生图提示词模板”, which are common user expressions and may cause the skill to activate in conversations where the user did not intend to invoke this specific behavior. Unintended activation can override normal assistant behavior, inject rigid stylistic constraints, and reduce user control, which is a genuine prompt-scope security and safety issue even though it is not overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The display name, short description, and default prompt are all written in Chinese, and the default prompt explicitly instructs the interaction in Chinese. There is no indication that the skill is region-specific or that users may choose another language, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill hardcodes an English output segment ("Cinematic lighting, Sunset backlighting...") inside an otherwise Chinese workflow, with no user opt-in or language choice. This can violate language/locale policy when a skill imposes a specific output language rather than adapting to user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.