Back to skill

Security audit

Paper Writing Workflow

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward academic paper-writing workflow skill with limited, disclosed local file output and no evidence of hidden execution, credential access, persistence, or data exfiltration.

Install only if you want a mostly Chinese-language paper-writing workflow. Expect it to guide other academic-writing skills and to create local markdown outline or draft files when you run its writing commands; review output paths before use if working in a sensitive directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises command-line usage that writes output files such as paper.md, polished.md, and reports, but it does not declare any tool scope like permissions or allowed-tools. In an agent environment, undeclared file-write capability weakens sandboxing and can let the workflow create or overwrite local files in ways the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown switches into Chinese for the primary workflow description and continues with Chinese headings and instructions, but it does not state that the skill is China-specific or provide an opt-in language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description and workflow metadata are presented in Chinese while also exposing English trigger phrases, but there is no statement that users may choose their preferred language. This can create a language/locale policy issue because the skill appears to assume a specific language experience without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes very broad, common phrases such as 'paper writing', 'thesis writing', and their Chinese equivalents, which can cause the skill to activate for routine academic-help requests even when the user did not intend to invoke this workflow. In a skill-chaining environment, unintended activation can misroute user requests, override a more appropriate skill, or launch a multi-stage workflow with assumptions the user did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains user-facing natural-language strings almost entirely in Chinese, including the title, stage names, and console output, but it does not offer any language or locale selection. That creates a language/locale policy concern because the skill effectively forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.