Back to skill

Security audit

nature-paper-workflow

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed academic-paper workflow router with no direct code execution, network use, or writes, though ambiguous prompts may be routed into publication sub-skills.

Install this only if you want a top-level academic-paper workflow router. For sensitive drafts, data, or reviewer materials, confirm the selected sub-skill before sharing content, because downstream sub-skills may have their own permissions and side effects even though this router is read-only.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad requests such as '帮我写论文', '帮我投稿', and '论文下一步该做什么', which can match ordinary academic-help prompts and activate this router when a more specific skill or normal assistant behavior would be more appropriate. Because this is a top-level router that can redirect into many sub-skills, accidental activation can misroute user intent, apply inappropriate defaults, and expand the action surface unnecessarily.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill applies implicit routing defaults for language/locale and venue handling, including Chinese-versus-English preferences and defaulting unspecified journal targets to Nature-series handling. Without explicit user opt-in, this can steer users into the wrong language, publication norm, or journal framing, creating integrity and privacy risks if later sub-skills generate content or advice under incorrect assumptions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad phrases such as literature review and paper download/card-related requests that can match ordinary research-assistance queries without an explicit workflow-routing qualifier. In a top-level router, this increases unintended invocation and misrouting risk, especially because the skill is designed to dispatch users into downstream capabilities across many phases.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The drafting trigger set uses generic requests like write abstract, write introduction, write methods, and cover letter, which are common across many unrelated writing contexts. Because this is a router spanning multiple branches and sub-skills, these unconstrained triggers can cause accidental activation and routing to the wrong drafting pipeline.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The polishing stage contains very generic phrases such as polishing, academic English, and sentence refinement that overlap heavily with normal editing requests. In a multi-skill router, that overlap can redirect users into a publication workflow when they only wanted localized editing help, creating incorrect skill selection and possible downstream disclosure of project context.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The Econ drafting triggers duplicate the same broad writing phrases used elsewhere, creating direct ambiguity between STEM and Econ branches for common requests like write abstract or write introduction. Even with discipline-routing rules later in the manifest, front-door trigger overlap raises the chance of inconsistent or incorrect branch selection before disambiguation occurs.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger term "起草" is overly broad for a router skill and can match many generic writing requests that are unrelated to the economics-paper workflow. In a routing context, this can cause unintended activation of specialized paper-writing sub-skills, leading to misrouting, user confusion, and execution of the wrong downstream behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Terms like "审稿意见", "返修", and especially "response" are generic and can refer to many non-academic or non-economics contexts. Because this file defines routing behavior, such broad triggers increase the chance of accidental escalation into reviewer/rebuttal flows for unrelated tasks, which is a genuine policy and routing-integrity risk.

Vague Triggers

Medium
Confidence
93% confidence
Finding
这些触发关键词包含“读论文”“找文献”“综述”“结论推导”等较宽泛表达,容易在普通学术对话中被误匹配,导致路由器在用户未明确请求该 skill 时被激活。虽然该文件本身是只读映射表、不直接执行高风险操作,但误触发会造成错误技能选择、越权上下文转交或与用户意图不符的后续流程。

Vague Triggers

Medium
Confidence
91% confidence
Finding
写作阶段中的“写摘要”“写引言”“投稿包”“结构修复”等描述缺少明确范围约束,和大量普通写作请求高度重叠,可能把非论文、非学术或非当前阶段的请求错误路由到相关子技能。作为顶层路由 skill,这类歧义会放大下游误用风险,因为错误分派会影响整个后续链路。

Vague Triggers

Medium
Confidence
90% confidence
Finding
“统计分析”“数据处理”“加引用”“数据声明”等关键词过于笼统,覆盖大量常见任务,可能使路由器在缺少上下文时选择错误的统计、数据或引用类子技能。虽然该 skill 声明不写入、不联网且只读子技能文件,使直接安全后果受限,但仍可能造成错误建议、流程偏转或将敏感学术内容交给不合适的子模块。

Vague Triggers

Medium
Confidence
94% confidence
Finding
Econ 分支中的“起草”“写引言”“表图设计”等触发词与 STEM 通用写作表达高度重叠,若没有学科判别逻辑,容易把一般论文请求误导向经济学专用子技能,或相反错过经济学专用流程。该文件又特别引入多分支共存与跨学科共享,使歧义匹配的实际概率和影响面更高。

Vague Triggers

Medium
Confidence
87% confidence
Finding
The Econ E-Phase trigger set includes very broad phrases such as '起草', '写摘要', '写引言', and '写方法', which are common across many general writing requests. In a top-level router skill, these unconstrained triggers can cause misrouting into economics-specific sub-skills without sufficient discipline confirmation, leading to inappropriate guidance, privacy overexposure to downstream skills, or bypass of more suitable workflows.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The cross-disciplinary shared triggers include generic phrases like '项目初始化', '投稿预检', '审稿模拟', '返修', and 'response', which can match many unrelated academic interactions. Because this file defines routing behavior for a top-level dispatcher, overly broad shared triggers increase the chance of unintended activation and context leakage to sub-skills, especially when the user's intent is ambiguous or only partially overlaps.

Static analysis

No suspicious patterns detected.