Back to skill

Security audit

Transcript Crafter

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Chinese WeChat article-writing workflow, but it defaults to copying and uploading transcript-derived output to Feishu cloud storage under the user's account without clear per-run consent.

Review before installing if you may process confidential interviews, meeting notes, personal data, or unpublished business material. Use it only if you want a Chinese WeChat-style workflow and are comfortable with web research, local output files, Desktop copies, and possible Feishu cloud upload; explicitly decline Feishu upload for sensitive work and verify sourced claims, especially preprints.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/pipeline-detail.md:461
Finding

Default Feishu Cloud Upload May Disclose Confidential Transcript Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as a transcript-to-article workflow, but it also performs local file duplication to the Desktop and uploads output to Feishu cloud storage. Those actions materially expand the skill’s data-handling scope beyond content transformation into persistence and third-party exfiltration, which is dangerous when transcripts may contain confidential interview material or personal data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document instructs the agent to run shell/CLI commands for file copying and lark-cli upload, granting capabilities that are unnecessary for summarization or rewriting. This broadens the attack surface from text processing to host-side file operations and external service interaction, enabling unintended data movement if the skill is invoked on sensitive content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and task section specify transforming transcripts into WeChat long-form articles in Chinese, and the entire output format is tailored to a Chinese公众号 format. There is no indication that users may choose another language or locale, so the skill imposes a language/locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is entirely a prescriptive writing policy in Chinese, with multiple absolute directives such as "永远", "绝对禁用", and style constraints that require one specific linguistic register. There is no user opt-in, language/locale choice, or documented justification that this restriction is region-specific, which matches the policy concern for forced language or locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is natural-language guidance, and its title and content enforce Chinese as the operating language without any opt-in or statement that the skill is region- or language-specific. Under the policy, forcing a specific language without user choice is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file title and all operational instructions are written exclusively in Chinese, and the prescribed output format uses Chinese labels, which indicates a fixed language expectation. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified, which this file does not do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
71% confidence
Finding

The workflow includes language detection but gives no option for preserving or selecting the user's preferred output language, and all natural-language instructions are framed for Chinese-language operation. This can amount to forcing a specific language/locale without explicit user opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow requires 100% incorporation of all supplemental information into the final article, which pressures the agent to include every user-provided detail regardless of sensitivity or relevance. In a writing pipeline, that increases the risk of natural-language leakage of confidential notes, personal data, or proprietary facts that should be filtered, minimized, or omitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow duplicates files locally and uploads them to a third-party cloud service without requiring a user-facing disclosure about additional copies, retention, or external transmission. Even if the actions are expected operationally, the lack of transparency and informed consent creates privacy and compliance risk for sensitive transcripts and derived articles.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Copying generated content to a user Desktop is a local persistence action that is not necessary to perform transcript analysis or article drafting. It creates extra plaintext copies in a highly exposed location, increasing the chance of accidental disclosure through shared machines, sync clients, backup systems, or shoulder-surfing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Uploading the final article to Feishu can transmit user-derived content to an external service without any required sensitivity screening of the transcript, quotes, or supplemental data. Because the skill handles interviews and source material that may contain confidential business discussions or personal information, automatic cloud transmission materially raises data leakage risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document title and all checklist instructions are written exclusively in Chinese, which establishes a single required language for operating the skill. There is no indication that users may choose another language or opt in to this locale, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing operational instructions exclusively in Chinese, and it does not indicate that the language is optional or region-specific. Under the policy rule for natural-language locale constraints, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill specification, templates, examples, and output format are written exclusively in Chinese, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire routing guide is written as a Chinese-only workflow and repeatedly prioritizes Chinese platforms and Chinese-language query patterns, but it does not state that this locale restriction is optional or region-specific. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file labels arXiv API results as '同行评审/官方预印本' and Tier 1, which materially overstates their reliability because arXiv hosts preprints that are not necessarily peer reviewed. This can cause the agent to treat unvetted claims as authoritative facts, increasing the risk of misinformation in generated articles.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a workflow for extracting interview content and turning it into a long-form WeChat article with search supplementation. Lines L093-L094 document mx-zixuan for watchlist management and mx-moni for simulated trading, which are finance account/transaction-style capabilities not justified by the skill’s stated content-processing purpose.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction that supplemental information '绝不留空' and should be preserved even as '[AI推断]' encourages the agent to surface unsupported generated content rather than maintaining evidentiary integrity. In a workflow meant to transform interviews into deep long-form articles, this is especially dangerous because readers may infer that all inserted details were researched and sourced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The fallback flow instructs the agent to use 'Agent 已知信息填充' and '[AI推断](绝不留空)' when no evidence is found. Even with internal labels, this normalizes fabrication as output completion behavior and creates a strong risk that unverifiable or false claims will be presented to end users in a polished article.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file instructs that original quotations must use Chinese corner quotes 「」, which imposes a specific locale/style convention in mandatory language. Because the guidance does not present this as optional or limited to Chinese-language公众号 output only, it reads as a forced locale requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.