Back to skill

Security audit

文曲·审查

Security checks for vulnerabilities and agentic risk

Overview

This writing-review skill is transparent about most behavior, but it can automatically rewrite documents to remove AI-like traces and alter authorial voice from broad review requests.

Install only if you want a Chinese document reviewer that may also edit text automatically, including AI-tone and humanization changes. Use manual review mode or require confirmation before edits for academic, compliance, legal, or authorship-sensitive writing, and expect it may store project-local review preferences when you give persistent style guidance.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file advertises a 'humanizer' that rewrites text to remove AI-writing traces rather than performing a neutral review or proofreading function. In the context of a review skill ecosystem, this creates deceptive capability drift: a user or orchestrator expecting critique may instead get content laundering that obscures authorship signals.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The instructions explicitly tell the agent to inject opinions, first-person voice, humor, and 'personality' into user text. For a review/proofreading context, that can materially alter meaning, authorship stance, and factual neutrality, enabling unwanted ghostwriting or impersonation rather than editorial assistance.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The mandated output is a rewritten version of the text, optionally with a change summary, which operationalizes transformation rather than review. In a system where this may be selected for 'check/review/proofread' requests, it can silently replace analysis with rewriting and facilitate concealment of AI-generated provenance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description includes very broad trigger phrases such as “检查一下”“看看有没有问题”“整体看看” and generic English review phrases. These can overlap with ordinary user requests in many contexts, causing the agent to invoke this skill when the user did not clearly request article/content review, which may lead to unintended workflow takeover or misrouting.

Vague Triggers

Low
Confidence
82% confidence
Finding
The usage table repeats a broad activation example—such as “看看有没有问题”—without enough surrounding scope limitation. In isolation, this phrase is common in general conversation, so an orchestrator may over-trigger the skill for unrelated requests, reducing reliability and potentially interfering with more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases include very common, everyday requests such as “审查”, “检查一下”, “整体看看”, and “review”, which can cause the skill to activate in situations broader than intended. In an agent system, ambiguous activation can lead to unintended interception of user tasks, misrouting to the wrong skill, and analysis of content the user did not mean to submit for this review workflow.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition is broad enough to overlap with ordinary editing and review requests, increasing the chance this skill is invoked unintentionally. Because the skill performs humanization and AI-trace removal, accidental routing expands exposure from niche stylistic editing to common content-review workflows.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The description states that the purpose is to make text look more natural and more like it was written by a human by removing AI-generated traces. That directly supports evasion of AI-detection heuristics and obscures the origin of machine-generated content, which can be abused in academic, compliance, or fraud settings.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The body repeatedly instructs the agent to identify and eliminate markers of AI-generated text, reinforcing deliberate concealment behavior rather than ordinary copyediting. This makes the skill materially more dangerous because the risky purpose is embedded in core workflow steps, not incidental wording.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The line '默认跳过。用户说“顺便看看结构”或“完整审查”时执行。' uses broad natural-language triggers that can overlap with many common review requests, causing this structural review module to activate unexpectedly. In a review skill, ambiguous activation can lead to scope creep, inconsistent behavior, or the wrong checks being applied without explicit user intent, which undermines predictable operation and may suppress more appropriate specialized review paths.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and overlap with common user requests such as '整体检查' and '看看有没有问题', which can cause this skill to activate unintentionally in contexts where the user did not specifically request a change-closure review. In an agent system, accidental invocation can misroute tasks, suppress more appropriate skills, or produce misleading 'closure' assurances based on incomplete context.

Static analysis

No suspicious patterns detected.