Back to skill

Security audit

daily-gushiwen

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public daily classical Chinese literature content and formats it for the user, with the main caveat that its trigger wording is broader than its daily-digest purpose.

Before installing, understand that generic Chinese poetry prompts may cause the agent to fetch gushiwen.cn and its image host and send formatted text or media. No credential access, local persistence, destructive action, or hidden install behavior was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description and trigger scope are broad enough to match common requests like '古诗' or '诗词推荐', which can cause unintended activation outside the narrow 'daily homepage digest' use case. This creates overbroad routing risk: the agent may invoke network scraping and formatted message delivery when the user likely wanted a general poem recommendation or literary discussion instead.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage section lists ambiguous activation scenarios without exclusions, so ordinary requests such as '古文推荐' or '今天有什么古诗' may spur this skill even when the user did not ask for website-fetched daily content. In context, this is more dangerous because the skill performs external fetches and may send media, increasing the chance of unnecessary network access, incorrect tool use, or user-surprising behavior from a loosely matched prompt.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains natural-language instructions and examples exclusively in Chinese, including output structure and formatting guidance. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation when no alternative or user choice is documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.