Back to skill

Security audit

We Chat Article Style

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable writing-style guide for Chinese WeChat/Zhihu articles, with no evidence of hidden code, data access, persistence, or destructive behavior.

Install this as a specialized Chinese WeChat/Zhihu article template. Review and edit the fixed author signature, QR-code reference, brand claims, and language/style assumptions before publishing content under your own name or for a different audience.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill hard-codes a Chinese-language公众号/知乎 writing style, audience, and formatting rules across the entire document without any indication that this locale constraint is conditional on user preference or deployment context. In an agent setting, this can override user intent, reduce usability for non-Chinese users, and cause unintended output-language or market targeting behavior.

Static analysis

No suspicious patterns detected.