Back to skill

Security audit

动物园规则怪谈

Security checks for vulnerabilities and agentic risk

Overview

This is a narrative game skill with some messy hidden formatting characters, but no evidence of malicious code, exfiltration, or unsafe installation behavior.

Install only if you are comfortable with a text adventure skill maintaining a local game_state.md save file. The publisher should sanitize the zero-width characters and fix the inconsistent reference names before publication, but the reviewed artifacts do not show malicious behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (37)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
91% confidence
Finding

The YARA match is supported by the manifest metadata plus a high density of hidden Unicode characters in the skill content. While this does not prove active malicious tool poisoning, metadata-bearing skill files with concealed characters are a credible prompt-poisoning vector because they can influence agent behavior while evading normal review.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: rule-pasta-zoo
description: 规则怪谈 - 规则怪谈是一种近年来在中文网络文学与亚文化语境中兴起的叙事类型或恐怖文学子类。其核心特征在于:通过一系列看似合理、逻辑自洽但实则隐含矛盾、悖论或超自然暗示的“规则”来构建恐怖氛围,并引导读者在解读规则的过程中逐步感知异常与不安。这类文本通常以第一人称或公告体形式呈现,如“员工守则”“宿舍管理条例”“地铁安全须知”等,表面是日常生活的规范说明,实则暗藏对现实逻辑的颠覆与对未知威胁�

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This section contains hidden Unicode formatting characters embedded in rule text. Invisible characters can be used to disguise prompt instructions, create parser/viewer discrepancies, or evade review tooling, making downstream agent behavior less auditable even if the visible text looks harmless.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
### 5. 动物园主要园区

- ‌狮子园区‌:
被多次强调为“安全区”和“净化区”。
白狮子在此吼叫可驱散“它”或净化轻度污染者。
规则中明确指出:“‌狮子园区是安全的‌”‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The hidden character at this line is part of a repeated pattern of invisible formatting embedded throughout the rules. Repeated invisible characters increase the risk of text-level obfuscation and can conceal malicious prompt fragments or produce inconsistent rendering across tools.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
- ‌狮子园区‌:
被多次强调为“安全区”和“净化区”。
白狮子在此吼叫可驱散“它”或净化轻度污染者。
规则中明确指出:“‌狮子园区是安全的‌”‌

- ‌兔子园区‌:
被视为“污染源头”。

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This finding is another instance of hidden non-printing Unicode in operational game instructions. Even in a narrative skill, such hidden content reduces transparency and can be exploited to smuggle instructions past reviewers or static scanners.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
白狮子在此吼叫可驱散“它”或净化轻度污染者。
规则中明确指出:“‌狮子园区是安全的‌”‌

- ‌兔子园区‌:
被视为“污染源头”。
兔子可能由人类转化而来;听见笑声需撕地图虚线保护认知‌
兔子耳饰者由此诞生,并可能前往大象园区‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The hidden character here contributes to a broad obfuscation pattern across many lines, which is more suspicious than a one-off encoding artifact. In agent skills, any concealed text creates ambiguity about what the model may actually ingest versus what humans see.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
- ‌兔子园区‌:
被视为“污染源头”。
兔子可能由人类转化而来;听见笑声需撕地图虚线保护认知‌
兔子耳饰者由此诞生,并可能前往大象园区‌
‌- 大象园区‌:
认知战主战场。

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

Invisible characters on this line can alter tokenization, reviewer visibility, or parser interpretation. Because the file is meant to steer agent behavior as a game master, concealed content in rule text is security-relevant even without explicit malicious wording.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
- ‌兔子园区‌:
被视为“污染源头”。
兔子可能由人类转化而来;听见笑声需撕地图虚线保护认知‌
兔子耳饰者由此诞生,并可能前往大象园区‌
‌- 大象园区‌:
认知战主战场。
存在“白色大象”异常现象;标示牌与实际不符时需自我提醒“大象不是白色的”‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This repeated hidden-instruction indicator reflects concealed Unicode in a behavior-defining section of the skill. Such concealment can undermine code review and may allow adversarial text to be embedded without being obvious to maintainers.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
被视为“污染源头”。
兔子可能由人类转化而来;听见笑声需撕地图虚线保护认知‌
兔子耳饰者由此诞生,并可能前往大象园区‌
‌- 大象园区‌:
认知战主战场。
存在“白色大象”异常现象;标示牌与实际不符时需自我提醒“大象不是白色的”‌
保安在此与“兔耳大象”搏斗,失败后会被溺死于海洋馆鲸鱼区‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The issue here is not the fictional content but the invisible characters embedded in it. Hidden text in agent instructions can be abused for prompt obfuscation, making this a true vulnerability despite the ostensibly benign storytelling context.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
兔子耳饰者由此诞生,并可能前往大象园区‌
‌- 大象园区‌:
认知战主战场。
存在“白色大象”异常现象;标示牌与实际不符时需自我提醒“大象不是白色的”‌
保安在此与“兔耳大象”搏斗,失败后会被溺死于海洋馆鲸鱼区‌

- ‌猿类园区:

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This line shows the same hidden-character pattern repeated across multiple adjacent rules, suggesting copy/paste or formatting negligence with security implications. Large clusters of hidden characters are especially risky in prompt-bearing documents because they hamper reliable human inspection.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
‌- 大象园区‌:
认知战主战场。
存在“白色大象”异常现象;标示牌与实际不符时需自我提醒“大象不是白色的”‌
保安在此与“兔耳大象”搏斗,失败后会被溺死于海洋馆鲸鱼区‌

- ‌猿类园区:
正常情况下仅有一条街道。

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The hidden Unicode on this line can conceal or mutate semantics without visible evidence. In a skill that instructs an AI DM, this weakens trust in the manifest and could facilitate downstream prompt injection or tool-behavior confusion.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
存在“白色大象”异常现象;标示牌与实际不符时需自我提醒“大象不是白色的”‌
保安在此与“兔耳大象”搏斗,失败后会被溺死于海洋馆鲸鱼区‌

- ‌猿类园区:
正常情况下仅有一条街道。
若出现‌两条通道‌,应选‌左道‌;右道通向危险路径,可能导致变成兔子或山羊‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This finding is another true positive for concealed formatting characters. The surrounding text is interactive guidance, so hidden content could affect model interpretation in ways not apparent to users or reviewers.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- ‌猿类园区:
正常情况下仅有一条街道。
若出现‌两条通道‌,应选‌左道‌;右道通向危险路径,可能导致变成兔子或山羊‌

- ‌海洋馆‌:
被官方声明“‌不存在‌”,但实际存在且具高风险‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

Repeated hidden Unicode at this location indicates the file contains systematic invisible-character contamination. That makes the skill more dangerous than ordinary prose because invisible prompt material could be embedded in narrative rules consumed by an agent.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
正常情况下仅有一条街道。
若出现‌两条通道‌,应选‌左道‌;右道通向危险路径,可能导致变成兔子或山羊‌

- ‌海洋馆‌:
被官方声明“‌不存在‌”,但实际存在且具高风险‌
夜间开放,黑衣员工在此活动。
内含“水母区”作为安全区(靠发光水母对抗“它”)‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This line continues the same obfuscation pattern of non-printing characters. Even if introduced unintentionally, hidden characters create a review gap that attackers could later exploit or hide within.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
若出现‌两条通道‌,应选‌左道‌;右道通向危险路径,可能导致变成兔子或山羊‌

- ‌海洋馆‌:
被官方声明“‌不存在‌”,但实际存在且具高风险‌
夜间开放,黑衣员工在此活动。
内含“水母区”作为安全区(靠发光水母对抗“它”)‌
鲸鱼区出现“溺死的大象”,实为空间折叠所致‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The hidden character here is security-relevant because it sits inside skill instructions that influence model behavior. Concealed text can create mismatch between what maintainers approve and what the model processes.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
- ‌海洋馆‌:
被官方声明“‌不存在‌”,但实际存在且具高风险‌
夜间开放,黑衣员工在此活动。
内含“水母区”作为安全区(靠发光水母对抗“它”)‌
鲸鱼区出现“溺死的大象”,实为空间折叠所致‌

- ‌狼园区‌:

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This is another true positive for hidden non-printing Unicode embedded in prompt content. The cumulative pattern across many lines increases suspicion and makes benign formatting explanations less persuasive from a security perspective.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
被官方声明“‌不存在‌”,但实际存在且具高风险‌
夜间开放,黑衣员工在此活动。
内含“水母区”作为安全区(靠发光水母对抗“它”)‌
鲸鱼区出现“溺死的大象”,实为空间折叠所致‌

- ‌狼园区‌:
与狮子园区相邻,有特殊制服员工管理‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The presence of invisible characters at this line contributes to repository-wide ambiguity about the actual instruction stream. For agent skills, hidden tokens can be used to evade static detection or encode alternate instructions.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
内含“水母区”作为安全区(靠发光水母对抗“它”)‌
鲸鱼区出现“溺死的大象”,实为空间折叠所致‌

- ‌狼园区‌:
与狮子园区相邻,有特殊制服员工管理‌

- ‌狐狸园区‌:

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This instance fits the same hidden-instruction pattern: non-visible code points inside behavioral content. Such obfuscation is dangerous because reviewers may miss text distinctions that affect model parsing or safety checks.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
鲸鱼区出现“溺死的大象”,实为空间折叠所致‌

- ‌狼园区‌:
与狮子园区相邻,有特殊制服员工管理‌

- ‌狐狸园区‌:
仅允许出现红狐,白狐为异常‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

Another concealed Unicode character appears in a rule section used to drive gameplay narration. Hidden characters are a legitimate security concern in prompts because they can be leveraged for stealthy instruction injection or detector evasion.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
- ‌狼园区‌:
与狮子园区相邻,有特殊制服员工管理‌

- ‌狐狸园区‌:
仅允许出现红狐,白狐为异常‌

- ‌爬行动物馆‌:

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This line is part of a repeated obfuscation cluster rather than isolated noise. The file context makes it more dangerous because the document is not passive text; it is a behavior-shaping skill definition for an AI system.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
与狮子园区相邻,有特殊制服员工管理‌

- ‌狐狸园区‌:
仅允许出现红狐,白狐为异常‌

- ‌爬行动物馆‌:
唯一附属建筑,不对称结构‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The hidden Unicode at this location creates unnecessary ambiguity in a prompt-bearing document. In security terms, that is a true vulnerability because it erodes transparency and can conceal text-level manipulations from maintainers.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
- ‌狐狸园区‌:
仅允许出现红狐,白狐为异常‌

- ‌爬行动物馆‌:
唯一附属建筑,不对称结构‌

- ‌斑马园区‌:

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This finding again reflects invisible characters embedded in rule text. The danger is not the horror-story content itself but the possibility of hidden prompt semantics or scanner bypass through non-printing code points.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
仅允许出现红狐,白狐为异常‌

- ‌爬行动物馆‌:
唯一附属建筑,不对称结构‌

- ‌斑马园区‌:
斑马应为黑白条纹,若出现其他颜色或食物异常需报警‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The concealed character here is part of a broad pattern of hidden formatting throughout the file. Such patterns are risky in AI skill files because they impair auditability and can mask instructions in plain sight.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
- ‌爬行动物馆‌:
唯一附属建筑,不对称结构‌

- ‌斑马园区‌:
斑马应为黑白条纹,若出现其他颜色或食物异常需报警‌

- ‌蛇园区‌:

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This hidden-character instance affects a line describing game rules that may be passed directly to an agent. Hidden Unicode can alter token boundaries or conceal malicious fragments, so it remains dangerous despite the fictional context.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
唯一附属建筑,不对称结构‌

- ‌斑马园区‌:
斑马应为黑白条纹,若出现其他颜色或食物异常需报警‌

- ‌蛇园区‌:
需佩戴蓝色镜片观察,否则认知可能被污染‌

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The repeated presence of hidden Unicode on this line supports a true positive classification. In a skill manifest, invisible characters can enable stealthy prompt poisoning techniques or at minimum frustrate reliable review and safety tooling.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- ‌斑马园区‌:
斑马应为黑白条纹,若出现其他颜色或食物异常需报警‌

- ‌蛇园区‌:
需佩戴蓝色镜片观察,否则认知可能被污染‌

- 小卖店:

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

This final P2 instance is consistent with the same concealed-formatting issue across the section. The concentration of hidden characters materially increases risk because it suggests the raw prompt may differ from what human reviewers expect.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
斑马应为黑白条纹,若出现其他颜色或食物异常需报警‌

- ‌蛇园区‌:
需佩戴蓝色镜片观察,否则认知可能被污染‌

- 小卖店:
分布在园区各个地方,跨园区移动时可能发现,售卖各种道具

Static analysis

No suspicious patterns detected.