Back to skill

Security audit

Wangwen Author Suite

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Chinese web-novel writing, review, and export skill with disclosed local file use and no evidence of hidden data theft or unsafe automation.

Before installing, expect the skill to manage local draft files under a novels directory and to run optional Python scripts for word counts or Fanqie TXT export. Confirm the target directory before export, because it writes TXT files and removes old TXT exports in the output folder. It is best suited for Chinese web-novel workflows and may activate on broad Chinese writing phrases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill instructs the agent to read and write local files such as `novels/[书名]/`, invoke local scripts, and access chapter files, but no explicit permissions are declared. That mismatch can cause the platform or user to underestimate the skill’s operational reach, increasing the risk of unintended file access or modification if the skill is auto-enabled.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The publish text advertises a long trigger list containing generic user phrases such as “写小说”, “起书名”, and “写简介”, which are common everyday requests and can cause the skill to activate when a user did not intend to invoke this specific package. Unintended invocation can route ordinary conversations into a specialized workflow, increasing the chance of prompt hijacking, data over-collection, or confusing behavior across unrelated contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README advertises activation on very broad phrases such as '写小说', '帮我写个小说', and generic references to writing assistance, which can cause the skill to activate during ordinary conversation without clear user intent. Over-broad routing increases the chance of unintended instruction takeover, context switching, or the model prioritizing this skill when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The feature table contains several ambiguous trigger phrases like '导出番茄', 'MD转TXT', '这段去AI化', and '这个skill有什么功能' without strong scope constraints. These phrases overlap with common requests and could make the agent enter this skill unexpectedly, especially when users are asking general-purpose editing or file-conversion questions.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The description advertises activation on broad phrases like writing novels, outlines, reviews, and export-related terms, which are common in normal conversation. Overbroad triggers can cause unintended activation, leading the agent to switch into this skill unexpectedly and potentially perform file-oriented actions or override the user’s intended workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The dedicated trigger section contains many ambiguous phrases such as `写小说`, `锐评`, `起书名`, and `MD转TXT`, plus parameterized examples, without constraints on context. Because the skill also contains operational instructions for reading local files and running export workflows, accidental activation is more dangerous than a purely conversational skill.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The examples and interaction flow are entirely in Chinese and do not offer a language-selection or fallback path, which can exclude or confuse users who invoke the skill in another language. This is not a code-execution or data-security issue, but it is a real safety/quality problem because it can cause misunderstandings, incorrect use of the skill, or inaccessible behavior for non-Chinese-speaking users.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The documented trigger phrases are broad enough to activate the skill for generic writing-related requests such as writing novels, outlines, reviews, or format conversion without clear scope boundaries. Over-broad activation can cause the agent to invoke this skill in contexts the user did not intend, increasing the chance of unintended file-operation guidance or content handling that is irrelevant, confusing, or unsafe in a multi-skill environment.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase guidance is broad enough to activate on common writing-related requests such as '起书名' or '写简介', which are not uniquely tied to this specific skill. That can cause unintended skill invocation, override user expectations, or route generic requests into a specialized workflow without clear consent.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The file is written to produce Chinese-only outputs and does not offer a language-selection step. While not a classic security flaw, this can create control and usability issues by disregarding user language preference, increasing the chance of unintended behavior or misleading outputs in multilingual contexts.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.