Back to skill

Security audit

Chinese Script Check Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese screenplay proofreading helper, with the main caution that it asks the agent to save script-derived notes as local files.

Before installing, understand that the skill may create local text and Markdown files containing details from your script. Use it in a workspace where retaining those notes is acceptable, and delete the generated files afterward if the screenplay is sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to save intermediate analysis artifacts locally (character_check.txt and scene_check.txt) without any user notice or consent. Because the input is a user-provided script, these files may persist sensitive, proprietary, or unpublished content on disk beyond the immediate task, creating unnecessary data retention and possible exposure to other tools, users, or later sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs writing the final review to QUESTION.md as a persistent local file without informing the user that their script-derived analysis will be stored. This can leak confidential screenplay content, editorial notes, or business-sensitive material into the local filesystem, where it may be unintentionally committed, indexed, or accessed by unrelated processes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.