Back to skill

Security audit

风咏

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only creative writing skill for adapting literature into songs, with no executable code, persistence, or sensitive access.

Safe to install for Chinese literary songwriting workflows. Users who want multilingual outputs or only source-text adaptation should be aware that the skill may activate on broad Chinese song-writing requests and tends to produce Chinese-formatted responses.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list mixes clear skill-specific phrases with broad everyday terms such as '写歌' and '编歌', which can cause the skill to activate in contexts the user did not intend. Unintended invocation can override a more appropriate skill, confuse routing, and lead to surprising behavior, especially because the skill produces long-form creative outputs rather than lightweight assistance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is written entirely in Chinese and prescribes Chinese-language structure and output without indicating that the user may choose another language. This can cause unwanted language switching, reduced usability, and prompt-level policy misalignment in multilingual environments, especially when an upstream system expects responses in the user's language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is entirely written as a prescriptive output-format template in Chinese, including required section labels such as "一句话", "歌词", and Chinese-language instructional notes. Because it presents the required output structure in a single fixed language and does not mention user opt-in or alternative locales, it creates a natural-language locale constraint that may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions, outputs, and trigger phrases are entirely Chinese-centric, and the skill does not state that language selection is optional or user-driven. This can be a language-policy issue if the organization expects skills not to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The document provides an AI music tool prompt in English ('epic chinese rock, male vocal...') as the direct pasteable prompt, while the rest of the skill is Chinese and there is no note that users may choose another language or locale. This can be interpreted as a language-policy issue because the skill prescribes a fixed prompt language without opt-in or alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all instructions and examples exclusively in Chinese, and there is no natural-language indication that users may choose another language or that the module is intentionally limited to a Chinese-speaking audience. Under the language/locale policy rule, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The section on AI-executable prompts requires translating the composition guidance into English prompt terms for tools like Suno/ACE, including fixed English examples and a mandatory ending phrase. This imposes a specific language for use of the skill without documenting user choice, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.