Back to skill

Security audit

Short Video Creation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese short-video creation guide with broad triggers, but it does not request hidden access, run code, persist, or handle credentials.

Reasonable to install if you want Chinese short-video creation assistance. Review the trigger phrases and replace the built-in persona, credentials, course offers, and marketing calls to action with your own verified facts before using generated scripts publicly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation conditions are broad enough to match common words like '视频', '脚本', and '内容创作', which can cause the skill to activate outside its intended context. Over-broad triggering can lead to inappropriate instruction injection into unrelated conversations, reducing system reliability and potentially overriding more suitable skills.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill content is written to operate in Chinese without indicating language negotiation or a documented locale restriction. This can cause the agent to respond in an unexpected language, creating confusion, degrading usability, and potentially causing the wrong skill behavior to be applied for users in other locales.

Static analysis

No suspicious patterns detected.