Back to skill

Security audit

Wanxiang Scroll

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a creative writing and interactive-story pack, but its optional local data scripts are under-scoped and can write outside intended story folders with crafted names.

Install only if you want a Chinese creative-writing/storytelling toolkit and are comfortable with local saves. Avoid running the crawler or data-management scripts on untrusted inputs; harden story-name validation before using the scripts for shared or automated workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/data_manager.py:59
Finding

Unrestricted Story Name Allows Directory Creation Outside the Stories Directory

Content
View full analysis
int: with self.db.get_connection() as conn: cursor = conn.cursor() cursor.execute(''' INSERT INTO stories (name, type, world_type, style, metadata) VALUES (?, ?, ?, ?, ?) ''', (name, story_type, world_type, style, json.dumps(metadata or {}))) conn.commit() story_id = cursor.lastrowid story_dir = STORIES_DIR / name story_dir.mkdir(parents=True, exist_ok=True) return story_id ``` ### Technical Analysis The `name` parameter is accepted from the command line and used directly as a path component. The code does not reject absolute paths, parent-directory components such as `..`, path separators, or symbolic-link-based escapes. Although `STORIES_DIR / name` appears to place the directory beneath the project’s `stories` directory, `pathlib` permits traversal components. An absolute `name` can also replace the preceding base path entirely. Calling `mkdir(parents=True)` then creates the resulting directory hierarchy wherever the running process has write permission. The SQL statement is parameterized and is not vulnerable to SQL injection. The vulnerability is specifically the subsequent filesystem use of the same untrusted value. ### Attack Path 1. An attacker or untrusted automation invokes the data manager’s exposed story creation command. 2. The attacker supplies a traversal or absolute path as the story name, for example: ```bash python scripts/data_manager.py create --type story --name "../../outside-directory" ``` An absolute path could also be supplied: ` ...[truncated 1304 chars]
Remediation
View remediation
Path: if not SAFE_STORY_NAME.fullmatch(name): raise ValueError("Story name contains unsupported characters") root = STORIES_DIR.resolve() candidate = (root / name).resolve() if candidate.parent != root: raise ValueError("Story directory must remain directly under STORIES_DIR") return candidate ``` Then replace the vulnerable operations with: ```python story_dir = safe_story_directory(name) story_dir.mkdir(parents=False, exist_ok=False) ``` Using `exist_ok=False` also prevents silently reusing an existing directory unless that behavior is explicitly required. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (208)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly declares itself 'ALWAYS ACTIVE (常驻后台)', which creates an effectively global behavior override rather than a scoped capability. In a prompt/agent setting, always-on instructions can unexpectedly hijack unrelated tasks, amplify other unsafe behaviors, and make it harder for higher-priority safety or task-routing logic to keep the skill dormant unless intentionally invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The /love_me [Name] command explicitly describes forcibly setting a target character's affection to maximum and locking it, which normalizes coercive, non-consensual relationship manipulation. In an agent skill context, this is dangerous because it encodes a direct pattern for overriding autonomy and can encourage generation of abusive roleplay or compliance with harmful coercive requests.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ch01-核心系统/03-quality-control.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ch01-核心系统/index.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ch05-文风系统/00-大数据包-56种文风完整.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ch07-质量控制/03-ai-trace-removal.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ch07-质量控制/index.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ch09-拆书融合/01-workflow-guide.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ch09-拆书融合/03-quality-and-rules.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/index.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/原始草稿/00-大数据包.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/原始草稿/12-AI文本净化终极指令集.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/原始草稿/index.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · saves/templates/quality_check.md (reported line 1)May include surrounding context.

md
# 质量检查模板

## 基本信息

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase “自然语言也行” indicates the skill can be invoked through unspecified free-form language rather than a clearly bounded command set. This makes activation scope ambiguous and increases the risk of unintended invocation during ordinary conversation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file mandates a rigid output format and stylistic constraints as an absolute rule ('铁律') without any indication that user preferences or higher-priority safety/system instructions can override it. In an agent skill, this can cause instruction-priority conflicts, reduce user control, and make the agent less able to comply with accessibility, localization, or safety-required response formats.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill file is written only in Chinese and does not indicate any option for the user to choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language activation examples are broad, everyday phrases such as '帮我打开菜单' and '我想探索森林', and the document explicitly states the system auto-detects intent with fuzzy matching. This increases the chance of unintended skill activation during ordinary conversation, quoted text, or discussion about the game, which can trigger state-changing actions without clear user confirmation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The fault-tolerance section explicitly allows broad semantic analysis, multiple expression forms, and fuzzy matching without clear trigger boundaries. In an interactive skill, this can cause command interpretation to bleed into normal conversation, leading to unintended state changes such as exploration, wishing, or role generation when the user did not intend to invoke a tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

L28 的格式规范要求输出固定使用中文引号和中文叙述样式,但未说明是否允许用户选择其他语言或区域设置。根据语言/locale 政策,若技能强制特定语言而未提供用户 opt-in 或合理限定,可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L30 写明“自然语言或斜杠指令都行。容错设计,模糊匹配”,但没有列出具体触发短语、适用范围或排除条件。对 markdown 文件而言,这属于模糊且过宽的激活说明,容易与日常表达重叠,导致技能在非预期场景下被调用。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill file is written as an instruction set that assumes Chinese-language operation and does not offer any user choice of language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L07-L09 将“自由行动”描述为“不受限制,说什么做什么”,这是高度宽泛的自然语言触发/使用范围说明,缺少何时适用、何时不适用的边界。文档也未提供排除条件或负面示例,容易与普通对话或任意请求重叠,导致技能调用范围不清。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states that gameplay interactions are silently converted into a complete novel in the background and can be viewed or exported, but it does not present this as a consented data-handling behavior or warn users up front that their inputs may be persistently transformed and retained. This creates a privacy and transparency risk because users may disclose sensitive roleplay, personal details, or dialogue they would not expect to be stored in an exportable narrative artifact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.