Back to skill

Security audit

文曲·翻译

Security checks across malware telemetry and agentic risk

Overview

This translation skill is mostly self-contained and purpose-aligned, with a disclosed but notable behavior of saving translation preferences into project files.

Installers should expect this skill to translate single-article English materials into Chinese and to ask about the target reader when needed. Be aware that reusable terminology or translation preferences may be written into a project-local wenqu-skills/.../preferences.md file, so review those files before committing a repository if preferences are private or project-specific.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to persist user translation preferences into project files under a computed path. This expands behavior beyond translation into filesystem modification and creates a data-retention side effect that may occur without explicit, contextual user consent, potentially leaking preferences into repositories or workspaces unexpectedly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.