Back to skill

Security audit

自然中文协议 (Natural Chinese Protocol)

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese text-editing skill that can broadly reshape prose style, but it contains only disclosed writing instructions and no code, credentials, data access, installs, or persistence.

Install this only if you want an optional Chinese prose naturalization/editing mode. Use it when tone changes are acceptable, and avoid applying it to legal, compliance, medical, academic, quoted, translation, or brand-sensitive text where exact wording, dialect, register, or disclosure must be preserved.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README explicitly states the protocol is broadly applicable to 'all general Chinese writing and communication scenarios,' which makes the skill's invocation scope unusually wide. In an agent setting, a broadly scoped rewriting rule can override user intent and silently transform outputs across unrelated tasks, creating style steering and policy drift rather than task-specific assistance.

Natural-Language Policy Violations

High
Confidence
91% confidence
Finding
The opening description presents the protocol as a 'core protocol' to eliminate AI traces and reshape Chinese expression, framing one specific writing norm as the default target state. In a skill ecosystem, this can pressure the agent to impose a locale/style preference without user opt-in, causing unauthorized transformation of content and reducing fidelity to the user's requested tone or audience.

Natural-Language Policy Violations

High
Confidence
93% confidence
Finding
These sections use mandatory phrasing such as '强制剔除' and '摒弃,' prescribing a fixed Chinese writing norm without any user choice. In practice, mandatory stylistic suppression can erase legitimate user preferences, regional variants, technical phrasing, or accessibility-oriented explicitness, making the skill more dangerous because it is designed for broad rewriting rather than a narrow editorial context.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill hard-codes Chinese as the operating language and instructs the agent to act only as a Chinese editing assistant, without any user-language negotiation or opt-in. This can override user expectations, reduce accessibility, and cause prompt-steering away from the user's preferred language, which is a genuine security/policy concern in multi-user or general-purpose agent environments.

Static analysis

No suspicious patterns detected.