Back to skill

Security audit

fiction-crafter

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese novel-writing helper that creates and updates story files, with no evidence of hidden credential access, network execution, or system persistence.

Install only if you want a file-backed Chinese fiction workflow. Review before using --clean because it removes generated Markdown chapters and resets story memory files in the skill workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个小说创作类技能,核心能力应是内容生成与长篇连贯写作;而实际代码仅进行 Markdown 章节文件中的分隔符清理,属于文件格式化/批处理工具。两者主目的完全不同。代码还会读取和改写本地文件、遍历目录处理多个章节文件,这种文件系统操作也未在描述中体现。不存在与声明相符的小说生成、剧情管理、图解生成或失败记录逻辑,因此属于明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/init-novel.sh (reported line 78)May include surrounding context.

sh
if [ "$CLEAN" = true ]; then
    log_step "清除旧的输出文件..."
    rm -rf "$OUTPUT_DIR"/*.md 2>/dev/null || true

    log_step "重置记忆文件..."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README advertises ./scripts/init-novel.sh 我的小说名 --clean without explaining what --clean deletes or resets. In an agent-driven environment, a cleanup flag can lead to destructive workspace modifications if an agent runs it automatically or if a user assumes it is harmless initialization.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill explicitly requires file read/write access and directs the agent to read and modify multiple files, but it does not declare a constrained tool scope such as permissions or allowed-tools. This creates excessive ambient authority: if auto-invoked, the skill can access or overwrite workspace files beyond what a user reasonably expects from a creative-writing helper.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation text is very broad, covering generic requests like writing stories or novels, which increases the chance the skill is auto-selected in ordinary conversations. Because the skill then instructs the agent to read/write persistent files and maintain state, over-broad triggering can cause unexpected file access or modification in contexts where the user only wanted simple text generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The metadata sets language: zh-CN, indicating a fixed language/locale preference. The document does not state that this is optional, user-selectable, or justified as a region-specific requirement, so it appears to impose a locale without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The initialization workflow states that init-novel.sh will clear old records in .learnings/ while preserving only template headers, but it does not require an explicit warning or confirmation at the point of use. This is dangerous because the skill maintains persistent story state there, so invoking initialization can silently destroy prior work, continuity data, or user-authored notes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file uses Chinese throughout for headings, instructions, and field labels, which effectively forces a specific language for users of the skill artifact. Under the policy, language constraints should either be optional for the user or clearly documented as a justified region- or locale-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file title and all template instructions are written entirely in Chinese and direct the review process in that language, but nowhere offers an opt-in language choice or explains that the skill is intentionally limited to a Chinese-language context. Under the policy rule, forcing a specific language without user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all instructional content are written in Chinese, and the template implicitly requires users to work in that language. There is no indication that Chinese is optional, user-selected, or required for a documented region-specific purpose, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and introductory description are entirely in Chinese and present the content as the default format, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstring states that when no output path is provided, the script defaults to overwriting the original file, and the implementation later writes directly to that path. Although usage text describes the argument forms, there is no confirmation prompt or strong user-facing warning before destructive in-place modification occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that the skill will automatically generate chapter files and persist story state in .learnings/, but it does not warn users that invoking the skill changes the workspace and leaves persistent artifacts behind. In an agent-skill context, undisclosed file creation and retention can surprise users, overwrite expected outputs, or leak sensitive prompt/content into project files over time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains natural-language instructions exclusively in Chinese, with no indication that users may choose another language or locale. Under the policy rule for language/locale constraints, forcing a specific language without user opt-in is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and command-line output strings are written only in Chinese, which imposes a single language on all users. There is no indication that this is a region-specific tool or any mechanism to select or opt into the locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.