Back to skill

Security audit

文曲·配图

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed image-generation workflow with expected installs, uploads, and article edits, though users should understand the external tools and Chinese-language defaults before using it.

Before installing, confirm you are comfortable with installing wenqu-cli/PicGo, using local image-provider credentials through the CLI, and uploading generated images to your configured image host. If you need English or Traditional Chinese labels, explicitly override the skill's Chinese-label defaults.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation phrases are broad everyday-language requests such as '生成图片', '渲染一下', and '帮我生图', which can cause the skill to trigger in contexts where the user may only be discussing ideas rather than authorizing image generation. Because this skill can lead to external CLI execution, network access, uploads, and file modifications, overbroad invocation increases the risk of unintended side effects and tool use.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The default style instruction says all text labels should be in Chinese, without conditioning that on the user's language or document language. This can cause silent output corruption, user-intent mismatch, or accidental disclosure of localization assumptions in generated assets, especially for English-language content or mixed-language workflows.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad everyday phrases such as '生成图片', '生成图片', and 'render it', which can cause the skill to activate in contexts where the user did not intend to invoke a workflow that installs software and performs uploads. In this skill, accidental activation is more dangerous because the workflow proceeds into environment detection, CLI installation, global tool checks, and external service interactions, increasing the chance of unintended system changes or data exposure.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow instructs installation of wenqu-cli, possible global installation of picgo, PATH modification, credential-file handling, and interaction with external upload services, but does not present a prominent consolidated warning about these system and supply-chain risks before the user enters the process. Because the skill frames the CLI as trusted and same-origin, users may under-appreciate the risk of installing software, changing global configuration, and enabling upload tooling that can affect the host beyond this task.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The template hard-codes '所有文字用中文' in the default prompt pattern, which can override or ignore the user's requested language. This is not a code-execution issue, but it is a real prompt-quality and policy-compliance weakness because it can cause incorrect outputs, accessibility problems, or failure to satisfy user requirements in multilingual contexts.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
Multiple reusable prompt snippets repeat a mandatory Chinese-language requirement regardless of user intent, creating a systematic behavior across diagram-generation flows. In this skill context, the issue is less dangerous than command injection or data exfiltration, but it can still reliably produce wrong-language artifacts and reduce usability, especially for English or multilingual requests.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The template hard-codes '文字标注全部用中文', which overrides user language preference and can cause the agent to ignore explicit instructions to generate diagrams in another language. In an image-generation skill, this is a prompt-quality and policy-compliance issue because it can systematically produce unusable or misleading output for non-Chinese contexts and may silently violate user intent.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The second template repeats a mandatory Chinese-only labeling requirement, creating the same systematic risk of disregarding user-specified language. Because this skill is triggered by both Chinese and English requests, the mismatch is more dangerous in context: English-speaking users may consistently receive diagrams with the wrong language labels.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The template hard-codes '文字标注全部用中文', which overrides user language preference and can cause the agent to ignore explicit requests for other languages. In an agent skill, this is a policy/quality vulnerability because it reduces user control and can produce unusable or misleading output for non-Chinese users.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This section again mandates that all labels be in Chinese, without checking user preference or conversation language. That can force language output inconsistent with the request, undermining expected behavior and making the generated diagram inaccessible to some users.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The template requires all annotation text to be Chinese in this flowchart mode as well, creating the same cross-language restriction across multiple rendering paths. Repeated mandatory language constraints increase the chance that the skill systematically ignores user instructions and locale expectations.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
The phrase '所有文字必须是简体中文,禁止繁体字' explicitly forbids other Chinese script variants without user opt-in, which is more restrictive than a simple default. This can directly conflict with user requests for Traditional Chinese and is especially problematic for users in locales where Traditional Chinese is standard.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.