Back to skill

Security audit

ZDAT Publish Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a publishing automation wrapper, but it includes platform-detection evasion guidance and lacks clear safeguards before public posting.

Review before installing. The skill may help publish content to public platforms and invokes an external local publishing engine, so only use it in a controlled workspace with trusted config and engine files. Remove the originality-check evasion instruction and add explicit confirmation or dry-run behavior before any scheduled or external posting action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a full-featured multi-platform publishing capability, including timed posting, format conversion, one-click dispatch, and publish logging across several external platforms. However, this code chunk only loads configuration from WORKDIR/skill_config/zd_publish_rule.yaml and prints a summary of platform rules to stdout. It explicitly says real publishing should be done via another script, indicating this file is informational rather than operational. There is no evidence of outbound platform publishing, scheduler logic, transformation/formatting logic, or persistent logging. Therefore, the supplied code chunk materially underdelivers relative to the declared purpose, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive cross-platform publishing skill wrapping a multi-publish engine, with scheduling, format conversion, distribution, and logging. The supplied code chunk only implements log viewing: it loads publish_log.xlsx via openpyxl and prints recent rows. While publish logging is mentioned in the description, this code does not publish content, schedule jobs, convert formats, or interact with any external platforms or publishing engine. Therefore the code chunk's actual behavior is materially narrower than the declared purpose, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a broad multi-platform publishing skill with several headline capabilities: timed publishing, format conversion, one-click distribution to multiple platforms, and publish logs. The supplied code chunk instead implements a narrow single-platform publishing script, as explicitly stated in its docstring and behavior. It loads platform-specific config from a YAML file and shells out to another script for publication, but there is no evidence in this chunk of scheduling, formatting/conversion, orchestration across multiple platforms in one run, or durable logging. The supported platform mappings also omit Douyin from the visible implementation. While calling an external engine is consistent with the general publishing domain, the actual code shown materially underdelivers relative to the declared primary purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The explicit phrase '规避各平台原创检测' indicates an evasion capability unrelated to legitimate publishing automation. In the context of a multi-platform distribution skill, this is especially dangerous because it could systematically help users bypass trust and moderation controls across several services.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/zd_publish_single.py (reported line 23)May include surrounding context.

python
"weibo": "weibo",
    }
    key = platform_map.get(platform, platform)
    return rules.get("platforms", {}).get(key, {})

def publish(platform, title, content):
    """调用发布引擎"""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises and demonstrates shell-based execution and file/log interactions, but it does not declare any explicit tool scope such as allowed tools or permissions. In an agent environment, missing tool scoping increases the chance that the skill can be invoked with broader-than-intended capabilities, enabling unintended command execution or filesystem access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger keywords are broad and likely to match many ordinary publishing requests, increasing the chance the skill activates in contexts the user did not intend. Because the skill is described as performing publishing and logging actions, overbroad activation can lead to accidental high-impact operations or exposure of content to shell/file workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The '去AI化处理' section explicitly includes evasion of platform originality-detection systems, which is a clear anti-detection objective rather than normal content formatting. Embedding detection-evasion guidance in a publishing skill encourages policy circumvention and can be used to launder spam, plagiarized, or deceptive content at scale.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Instructing the system to rewrite content specifically to evade originality or AI-detection checks is a harmful stealth capability. Within a cross-platform publishing skill, this materially increases abuse potential by enabling non-compliant content distribution while reducing the chance of platform detection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation describes automatic publishing and writing to publish_log.xlsx without any explicit warning, confirmation gate, or safe-mode behavior for data-changing actions. In an agent setting, this can cause unintended external posting or persistent local changes if the skill is invoked implicitly or on ambiguous user input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language description states the script is a Chinese-language publishing tool and all user-facing strings are in Chinese, with no indication that language selection is optional. This creates a locale/language policy concern because the skill appears to enforce a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/zd_publish_single.py (reported line 36)May include surrounding context.

python
# 调用 v5 发布引擎
    script = str(WORKDIR / "zd_auto_publish_v5.py")
    if os.path.exists(script):
        result = subprocess.run(
            ["python", script, "--platform", platform, "--title", title, "--content", content],
            capture_output=True, text=True, timeout=120
        )

Tainted flow: 'script' from os.getenv (line 34, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
89% confidence
Finding

The executed script path is derived from WORKDIR, which comes from an environment variable and is therefore attacker-influenceable in many automation or agent contexts. If an attacker can control WORKDIR or place a malicious zd_auto_publish_v5.py in the resolved location, this code will execute arbitrary Python code with the privileges of the current process.

Content

Scanner excerpt · scripts/zd_publish_single.py (reported line 36)May include surrounding context.

python
# 调用 v5 发布引擎
    script = str(WORKDIR / "zd_auto_publish_v5.py")
    if os.path.exists(script):
        result = subprocess.run(
            ["python", script, "--platform", platform, "--title", title, "--content", content],
            capture_output=True, text=True, timeout=120
        )

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring is written entirely in Chinese and presents the skill purpose only in that language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative or locale choice is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module docstring and all user-facing messages are written only in Chinese, indicating a fixed language choice for interaction. The file does not offer a language option or explain that the skill is intentionally region-specific, which can violate the language/locale policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.