Back to skill

Security audit

Paper Checking

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent document-plagiarism checking helper that relies on a user-installed Windows executable and disclosed user-selected files, with no evidence of hidden execution, exfiltration, or destructive behavior.

Install only from the referenced upstream source you trust, and avoid running confidential theses, bids, or internal documents unless you are authorized to process them with this local tool. Review preprocessing settings such as keyword filtering and non-Chinese character removal before relying on the similarity score, and keep track of where RTF/CSV reports and temporary recovery files are written.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly states that the AI will analyze user files, execute plagiarism checks, and generate reports, but it does not clearly disclose that sensitive document contents will be processed by an external executable and may be written to output files on disk. In a document-review context such as theses, bids, or internal enterprise materials, this omission can lead users to expose confidential or regulated data without informed consent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guide states that configured keywords are automatically deleted before comparison, but it does not clearly warn users that submitted text is being materially altered for analysis. In a plagiarism-checking context, this can mislead users about what content was actually examined and can cause inaccurate results or unintended omission of important terms, especially for academic or institutional names.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The documentation points users to third-party URLs and an external SDK repository without warning about privacy, supply-chain, or data-handling implications. In a paper-checking product, users may process sensitive unpublished manuscripts, so silently encouraging external integrations can expose confidential academic content or introduce unreviewed dependencies.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The preprocessing rule says non-Chinese characters are deleted, but the guide does not state scope limits, language assumptions, or the risk of corrupting multilingual content. For academic papers, removing English terms, formulas, citations, identifiers, or mixed-language passages can materially distort the text and produce incorrect plagiarism results or loss of key semantic content during analysis.

Static analysis

No suspicious patterns detected.