Back to skill

Security audit

小说风格续写

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese novel-continuation skill that stores local style and plot notes for continuity, with no scripts, network behavior, or hidden system-level actions.

Install only if you want a Chinese-language novel-continuation workflow that can save local style and plot notes. Review or clear the references files if the manuscript is sensitive, proprietary, or should not persist between sessions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match many ordinary creative-writing requests, which can cause this skill to activate unexpectedly outside a clearly consented context. That increases the chance the agent will follow this skill's file-read and file-write workflow when the user only asked for general writing help, creating unnecessary workspace access and persistent state changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to create or update reference files as part of normal operation, but it does not require clear user notice or consent before writing persistent data. This is dangerous because it can silently store user-provided copyrighted or sensitive text-derived information in the workspace, and that state may later influence other runs or expose information unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Automatically creating references/plot_state.md when it does not exist introduces persistent workspace modification without prior approval. This is risky because even derived summaries of story state can contain sensitive or proprietary material from the user's manuscript, and automatic creation makes the write happen by default rather than as an informed opt-in action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file content is entirely in Chinese, beginning with a Chinese title, with no indication that language choice is optional or limited to a justified region-specific context. This can violate a language/locale policy when a skill or reference material imposes one language without offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and style guidance exclusively in Chinese, and there is no indication that users may opt into another language or that the file is intentionally limited to a Chinese-language workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.