Back to skill

Security audit

Creative Fiction Writer

Security checks for vulnerabilities and agentic risk

Overview

The skill mainly provides adult-fiction writing guidance, but it also tells the agent to automatically save sensitive generated stories to a local plaintext file without asking first.

Review before installing if you would not want adult stories or prompts saved on disk automatically. The main concern is privacy from local persistence, not evidence of malware; safer behavior would be to return stories in chat and save only after explicit confirmation with a chosen path.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:46
Finding

Automatic Plaintext Persistence of Sensitive Generated Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a creative-writing assistant, but it also instructs the agent to automatically persist generated content to a local filesystem path. That side effect is outside the core user-visible purpose and can cause sensitive or explicit user content to be stored without informed consent, creating privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic creation of directories and files is not necessary to fulfill the stated function of generating erotic fiction text. Unnecessary file-system access expands the skill's capabilities beyond content generation and increases the chance of privacy leaks, unexpected disk artifacts, and misuse of local storage for content the user may consider highly sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes automatic saving behavior without any warning, consent flow, or confirmation prompt. Because the content is erotic and potentially highly sensitive, silent persistence materially increases the risk of embarrassment, privacy compromise, and retention of data the user did not intend to store.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.