Back to skill

Security audit

Chinese Humanizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about being a Chinese rewriting tool, but some “successful” examples teach it to add unsupported facts despite its no-fabrication rules.

Review outputs carefully for newly introduced specifics. This skill may be useful for Chinese editing, but do not rely on it for business claims, technical documentation, academic submissions, applications, or personal statements unless every added fact, capability, event, source, and result is verified or supplied by you.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/examples.md:9
Finding

Reference Examples Encourage Unsupported Factual and Personal-Experience Fabrication

Content
View full analysis
Against the backdrop of continuing digital transformation, this platform not only provides enterprises with end-to-end data capabilities, but also uses an intelligent engine to empower organizations to reduce costs and improve efficiency, helping businesses enter a new stage of high-quality development. **Failed rewrite** (only replaces words; the structure remains unchanged) > As digital transformation continues, this platform provides enterprises with comprehensive data capabilities and uses an intelligent engine to help organizations reduce costs and improve efficiency, advancing the business into a higher-quality stage. **Successful rewrite** > This platform puts orders, inventory, and reconciliation in the same administration interface. After sales staff enter information, operations and finance can continue directly without repeatedly completing spreadsheets. The most visible change for the team is switching between fewer systems and completing month-end reconciliation faster. Why it succeeds: It replaces “empowerment/end-to-end/cost reduction and efficiency improvement” with roles, actions, and results; the evidence density is higher, making it resemble a real product description rather than an investor presentation. ``` The original does not establish that the platform combines orders, inventory, and reconciliation, or that it eliminates spreadsheet work and accelerates month-end reconciliation. #### Content-writing example — lines 23-29 ```markdown **Original** > On the one hand, this phenomenon refle ...[truncated 6341 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, and default prompt all constrain the skill to rewriting Chinese text, and the prompt explicitly instructs use for a Chinese draft. This is a language-specific restriction presented as the default behavior without offering the user a language choice or documenting an opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L03 includes a blanket instruction in Chinese that effectively sets writing-style constraints and language expectations without offering the user a choice of language or locale. Under the policy, forced language or locale behavior should be flagged unless the file clearly documents an opt-in or justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction says that without a writing sample, the assistant should use 'restrained, natural, genre-fit Chinese.' This imposes a specific language choice as a default behavior without offering the user a language/locale choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The draft skill is explicitly defined as a Chinese-only editor (for example, name: chinese-humanizer, description: 将中文 AI 草稿改写..., and 你是一名中文编辑) without offering the user a language choice or stating that the skill is limited to a justified Chinese-only deployment context. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · research/report1.md (reported line 17)May include surrounding context.

md
# 2. 关键结论

| 结论                                                            | 证据类型        | 依据                                                                                                       |
| ------------------------------------------------------------- | ----------- | -------------------------------------------------------------------------------------------------------- |
| AI 文本检测是概率判断,不适合作为唯一依据                                        | 研究 + 官方说明   | OpenAI 分类器下线;Turnitin/GPTZero 都强调非最终裁决。([OpenAI][1])                                                     |
| Perplexity、burstiness、token distribution 能解释部分 AI 味,但不能等同“人味” | 研究支持        | DetectGPT、Fast-DetectGPT、Turnitin 的词概率序列说明都基于模型生成分布差异。([arXiv][4])                                       |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This activation example is broad natural language that could apply to many everyday rewriting requests, not just this skill's narrowly intended use. Because it lacks scope limits or negative examples, an agent may invoke the skill for ordinary polishing tasks or deceptive-authorship requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and opening lines present the skill content as a Chinese-native taxonomy while still embedding English guidance, but there is no explicit user opt-in for language or statement that the skill is intentionally region/language-specific. Under the stated policy, forcing or assuming a language/locale without choice or clear justification can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents the skill content in Chinese while also using some English labels, but it does not state that the skill is Chinese-only or provide any user opt-in for language preference. Under the policy rule, forcing a specific language without user choice can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

In the trigger list, this phrase is not specific to AI-style rewriting and could match ordinary writing-improvement requests outside the skill's intended scope. The surrounding list is mostly more specific, but this item weakens activation precision by lacking constraints or exclusion examples.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Within the embedded SKILL.md draft, this wording is generic enough to overlap with common editing or copyediting requests unrelated to AI-tell removal. Although other lines add context, this phrase itself lacks specificity and could contribute to over-triggering if copied into a real manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The report notes meaningful differences across Mainland, Taiwan, Hong Kong, and Singapore Chinese, yet the proposed behavior stops at saying the skill 'should let the user specify' regional style later. Without an explicit opt-in requirement, a deployed skill based on this guidance may default users into a specific locale variant, which is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.