Back to skill

Security audit

Wanxiang Scroll Creation

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only Chinese web-fiction writing skill with no local execution, but it includes explicit AI-detector evasion guidance users should review before installing.

Install only if you specifically want a Chinese web-fiction generation and editing workflow, and be aware that parts of it are designed to make AI-written text look less detectable. Do not use it to bypass platform disclosure, moderation, academic, or authorship rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (18)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/chapter-07-quality-control/02-editor-techniques.md (reported line 1)May include surrounding context.

md
# 第五章:创作引擎

本章包含Apex创作引擎、直接告知法和去AI化写作技巧,用于提升创作质量和文本自然度。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/chapter-07-quality-control/index.md (reported line 1)May include surrounding context.

md
# 第五章:创作引擎

本章包含Apex创作引擎、直接告知法和去AI化写作技巧,用于提升创作质量和文本自然度。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/index.md (reported line 1)May include surrounding context.

md
# 第五章:创作引擎

本章包含Apex创作引擎、直接告知法和去AI化写作技巧,用于提升创作质量和文本自然度。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s name, description, headings, and feature list are entirely in Chinese and target Chinese web-fiction platforms such as 知乎、起点、晋江, but the file does not state that this locale restriction is optional or region-specific. Under the policy, forcing a specific language/locale without user opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L137 states '使用简体中文创作' as a required identity/quality check, which forces a specific output language. The file does not offer any user choice or opt-in mechanism for language, so this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L098 states '避免输出繁体字', which imposes a language/script restriction in natural-language instructions. This is a locale/language policy issue because it forces a specific script choice without offering the user any option or documenting a justified region-specific need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire workflow and prompt templates are written exclusively in Chinese and present the skill as operating in that language by default, with no opt-in or alternative locale guidance. Under the policy, forcing a specific language without user choice is a natural-language locale violation unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all instructions, examples, and usage guidance exclusively in Chinese, which effectively forces a specific language on users. The policy allows language constraints only when users are given a choice or when the locale restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file is entirely framed as Chinese-language writing instructions and examples, and it presents the skill as a prescriptive writing framework without any indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction 朱雀v3检测置信度<30% is a detector-evasion objective, not a legitimate writing-style requirement. Embedding a target to score below a named detection system encourages optimization against safety or quality screening, which can help conceal policy-violating, spammy, or manipulative generated content and undermines downstream trust controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document explicitly instructs writers to use Chinese quotation marks and a platform-specific Chinese writing style, which constitutes a fixed language/locale requirement in natural-language guidance. Because it does not present this as an opt-in choice or clearly justify the locale constraint as a region-specific skill, it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

A language-only presentation can violate organizational language/locale policy when it effectively forces a specific language without user opt-in. This file contains all instructions and descriptions in Chinese and does not state that the skill is region-specific or offer an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L019 requires dialogue to use Chinese corner quotes 「」 and frames this as a uniform formatting standard. Because the file is a general writing quality standard rather than a clearly region-specific tool, this imposes a specific locale/style convention without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file contains natural-language instructions that force the assistant into a particular Chinese colloquial persona and output style ("你现在是一个有才华但喝了酒的网文作者"). Under the policy rule for language/locale constraints, the skill does not provide any user opt-in or alternative language choice, so it can impose a fixed language/style behavior on users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown skill explicitly frames multiple rules as Chinese-specific defaults, such as stating that Chinese titles and quotation practices are the expected norm. Because the file presents these conventions as the operating standard and does not offer a language or locale choice, it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire skill document is written in Chinese and presents all guidance exclusively in that language, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly bans Traditional Chinese and mandates Simplified Chinese output without presenting it as a user-selectable preference or documenting a necessary locale restriction. This creates an unnecessary language-access constraint and can improperly override user needs or platform context, though it is not a classic security exploit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to use Simplified Chinese for creation is imposed as a mandatory rule without opt-in or clear justification. In an agent skill, this can cause the model to ignore user language preferences and reduce safe, appropriate adaptability across audiences and regions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.