Back to skill

Security audit

Longform Writing by Emberspun

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed longform-writing memory workflow that stores manuscript continuity data locally for its stated purpose.

Before installing, verify that you are comfortable running the disclosed npm MCP server and storing your manuscript text in local plain files. Use the same project name consistently and follow the skill's instruction to refresh thread listings before resolving or progressing them.

Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Session Persistence

Medium
Category
Rogue Agent
Content
setups, "we'll cover this later".

The reply numbers them `[T1] [T2] ...`. **That numbering is only valid for the
chapter number you passed.** If you list at chapter 12 and then write chapter 13,
list again before referring to a `[T#]` - otherwise "resolve T2" may land on a
different thread than the one you meant, which is worse than not matching at all.
Confidence
80% confidence
Finding
The skill relies on session-scoped identifiers like `[T#]` that are only valid for a specific chapter state, creating a statefulness hazard. If an agent or user reuses stale references across steps or sessions, it can update or resolve the wrong narrative thread, causing integrity errors in persistent local memory and making subsequent recall/continuity checks unreliable.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.