Back to skill

Security audit

AI Content Brief, Script & Outline Generator — Research Assistant for Video & Image generation

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed knowledge base, but it includes guidance to route sensitive image requests to more permissive providers.

Review the model-selection guidance before installing. The skill is useful for IMA Studio planning, but users should not rely on its recommendation to choose providers because they are more permissive for sensitive or real-person image tasks; apply the strictest applicable content-safety rules regardless of provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (33)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The example scenarios present user requests only in Chinese, which implies a specific language context for interacting with the skill. Because this markdown does not state that the skill is China-specific or offer any language/locale choice, it can violate the language/locale policy for natural-language guidance.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The specialized directory descriptions on these lines are presented in Chinese while the rest of the README is in English. This creates a language/locale constraint in the skill documentation without user opt-in or an explicit statement that the skill is intended for Chinese-speaking users only.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This manifest description presents the skill as a general-purpose 'AI research assistant' that 'provides expert guidance' and is 'essential reading' for a wide range of planning tasks, but it does not define specific trigger phrases, scope boundaries, or exclusion conditions. In a manifest context, this broad wording can match many ordinary requests about planning, model choice, or workflow advice and may cause unintended invocation.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This markdown file presents all operational instructions and examples in Chinese, and does not indicate that users or agents may choose another language. Under the policy category, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
This file is entirely in Chinese and does not provide a language choice, translation, or opt-in despite being part of a broadly described skill. Users who cannot read Chinese may misunderstand instructions, miss limitations, or be unable to safely and effectively use the guidance, which creates accessibility and usability risk. In this context the content is non-executable best-practice guidance, so the issue is less dangerous than code execution or prompt-injection flaws, but it is still a real quality and safety problem.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This markdown file is predominantly Chinese-language instructional content, with only limited English terms mixed in. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This README uses Chinese throughout for headings, instructions, examples, and operational guidance, which effectively forces a specific language on users or agents consuming the skill. The policy allows locale constraints only when explicitly justified or when the user is given a language/locale choice, neither of which is stated here.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This markdown file presents nearly all substantive guidance in Chinese, with only minimal English glosses, which can amount to a language/locale policy violation when users are not given an explicit language option. The file does not state that it is intentionally region-specific or provide an opt-in mechanism for Chinese-only content.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The file states it is used as a basis for IMA Studio AI content generation, and the document content is written in Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in can be a violation; this file does not mention any language selection, alternatives, or opt-in.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The title and purpose statement present the guide entirely in Chinese for use as a color-selection basis in AI content generation, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
This markdown file presents all substantive guidance in Chinese and does not state that the language is optional, user-selected, or limited to a Chinese-speaking workflow. Under the policy for natural-language issues, forcing a specific language without opt-in can be a locale-policy violation.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This README is entirely written as Chinese-only operational guidance for the agent, including its usage flow and examples, with no indication that users may request another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
Line L088 states '中国市场2026Q1必用色' ('must-use color'), which imposes a locale-specific requirement in natural language rather than presenting it as optional guidance. The policy for this audit forbids forcing a specific language or locale without user opt-in unless the regional constraint is clearly justified as a region-specific tool; here the document is a general reference file and does not frame the requirement as optional or scoped-only guidance.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The README is entirely in Chinese and does not offer an alternative language or explain a locale-only constraint. In a broadly distributed agent skill, this can prevent reviewers and users from understanding operational guidance, increasing the risk that unsafe or inappropriate behavior in linked modules goes unnoticed or is misused due to misunderstanding.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file contains guidance and operational instructions solely in Chinese, aside from a few model names and headings. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Ssd 4

Medium
Confidence
93% confidence
Finding
The guide explicitly recommends choosing a relatively more permissive provider for '真人照片加工、性感元素等敏感任务' and frames policy-restricted or sensitive content as a provider-selection problem. In a planning skill, this can normalize or facilitate policy evasion by steering users toward weaker safeguards for sensitive image generation, increasing the likelihood of abusive or non-compliant outputs.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The guide explicitly instructs the system to implicitly translate non-English prompts into English without obtaining user approval. This can alter meaning, lose nuance, or mishandle safety-critical terms, especially when the prompt contains exact wording, legal text, brand names, or multilingual content that must be preserved. In a planning skill that shapes downstream AI-generation prompts, silent translation increases the risk of user-intent corruption and unsafe or noncompliant outputs.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The entire skill content is written in Chinese and does not provide any indication that users may request another language or locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file contains user-facing instructional content exclusively in Chinese, and it does not provide any opt-in, alternative language, or explanation that the skill is intentionally region-specific. Per the policy, forcing a specific language without user choice is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
This markdown file is written as an instructional skill reference and presents its guidance entirely in Chinese, beginning with a Chinese title, without any note that the language is optional or region-specific. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This markdown file includes user examples and suggested agent responses in Chinese, and the document does not state that the skill is China-specific or that users may choose their preferred language. That can amount to a language/locale policy violation because it implicitly forces one language without user opt-in.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
This markdown file is natural-language guidance and all user-facing instructions, headings, and examples are written in Chinese. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation, and the file does not indicate that the skill is region-specific or that other language options are available.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
This markdown file is entirely written in Chinese and does not indicate that other languages are supported or that the user can opt into a different language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file presents all instructions and guidance in Chinese, but it does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
This markdown file presents all substantive guidance in Chinese and does not indicate that users may choose another language. The policy requires flagging language or locale constraints when a skill effectively forces a specific language without user opt-in.

Static analysis

No suspicious patterns detected.