Back to skill

Security audit

Wenyan Compress

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple text-rewriting/compression aid with no evidence of hidden access, persistence, network use, or destructive behavior, though its bundled Python helper appears incomplete.

This appears safe to install from a security perspective, but do not rely on the bundled Python helper for actual compression, privacy reduction, fidelity checking, or token statistics. Treat the skill as an LLM prompt/instruction aid and verify outputs before using it for sensitive, legal, financial, or exact-data material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个可实际执行的文言文压缩技能,并且额外支持保真模式、压缩比统计、忠实度检查。但代码中核心函数compress_to_wenyan并未完成压缩逻辑,也没有模型API调用,只是返回“需要调用大模型处理”的占位文本以及原始输入和风格参数。因此其实际行为与声明的主要用途存在实质不符。此外,声明中的三项附加能力在代码中完全没有实现。代码没有表现出额外未声明的敏感能力或权限访问问题;主要问题是声明功能明显多于实际行为。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill converts Chinese or English input into concise Classical Chinese, and the rest of the document consistently presents Wenyan output as the mandatory result. Because the skill accepts English input but does not offer an option to preserve the user's original language or explicitly require opt-in to Chinese/Classical Chinese output, it creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module description states that the skill compresses input into 文言文, and the prompt text consistently instructs the model to rewrite content in that specific language form. This is a natural-language locale/language constraint with no user opt-in or alternative language option, which matches the policy-violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises compression with fidelity/statistics capabilities, but the implementation does not perform any compression and instead echoes the full user input in a placeholder response. This is dangerous because downstream users or agents may trust the declared behavior and inadvertently expose sensitive input text, defeating privacy/token-reduction expectations and causing unsafe data handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments and docstrings state that the function invokes an LLM for compression, but the code never does so and returns a mock string containing the original text. This mismatch can mislead reviewers, orchestrators, or users into treating the output as transformed/sanitized when it is not, increasing the risk of accidental data leakage or policy bypass in larger agent pipelines.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.