Back to skill

Security audit

Murder Mystery Creator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent murder-mystery generator, but it asks the agent to persist generated analysis into trusted skill reference files and produces a shared HTML visualization that can expose private player material and execute unsafe page content.

Install only after reviewing the persistence and HTML-output behavior. Do not allow the skill to modify its own reference markdown as a cache, treat generated visualizations as host-only unless private fields are removed, and avoid opening or sharing generated HTML that contains untrusted text until the template escapes dynamic content and vendors or pins D3 with integrity checks.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T02 · Agent Memory Poisoning

Error
Location
references/professional-analysis-framework.md:425
Finding

Persistent poisoning of the Skill analysis cache

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/visualization-template.html:349
Finding

DOM-based HTML and JavaScript injection in generated visualizations

Content
View full analysis
{ const card = document.createElement('div'); card.className = 'char-card'; card.onclick = () => showCharModal(c); card.innerHTML = `
${c.name[0]}
${c.name}
${c.role || ''}
${c.desc || ''}
`; grid.appendChild(card); }); } function renderTimeline() { const tl = document.getElementById('timeline'); tl.innerHTML = ''; DATA.events.forEach(e => { const item = document.createElement('div'); item.className = 'tl-item'; item.innerHTML = `
${e.time || ''}
${e.title || ''}
${e.desc || ''}
`; tl.appendChild(item); }); } function renderClueCards(filter) { const grid = document.getElementById('clue-grid'); grid.innerHTML = ''; const clues = filter === 'all' ? DATA.clues : DATA.clues.filter(c => c.type === filter); const typeNames = { C: 'Physical evidence', M: 'Testimony', T: 'Time evidence', W: 'Other' }; clues.forEach(c => { const card = document.createElement('div'); card.className = 'clue-card'; card.innerHTML = `
${typeNames[c.type] || c.type} · ${c.id || ''}
${c.name || ''}
${c.desc || ''}
Related: ${(c.relatedChars || []).joi ...[truncated 3362 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/visualization-template.html:7
Finding

Unpinned remote executable dependency without integrity verification

Content
View full analysis
``` ### Technical Analysis The visualization downloads and executes D3 from a third-party CDN whenever the page is opened. The dependency is constrained only to the floating major version `7`, not an exact reviewed release. The script element also lacks a Subresource Integrity hash. As a result, the effective code executed by the generated page can change after the Skill package has been audited. Compromise of the CDN, package publication process, account, or version-resolution path could substitute code that executes in every generated visualization. The generated page also depends on network availability even though its presentation suggests that users can open it directly in a browser. ### Attack Path 1. The remote package, CDN account, distribution infrastructure, or major-version resolution is compromised or altered. 2. A user opens a generated visualization while connected to the network. 3. The browser requests `d3.min.js` from the remote CDN. 4. The browser executes the returned JavaScript without cryptographic verification. 5. Substituted code runs with the same browser-origin access as the visualization. ### Impact Assessment Compromised dependency code can read and modify all data in the visualization, including character information, clues, private scripts, and hidden goals embedded in the document. It can also make arbitrary network requests permitted by the browser and page security policy. The issue does not independently grant native operating-system privileges. Its scope is the generated page's browser context and any data or authenticated resources available to that origin. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/visualization-template.html:202
Finding

Private player scripts and hidden goals exposed in a shared HTML document

Content
View full analysis
{ const item = document.createElement('div'); item.className = 'script-list-item' + (c.name === DATA.victim ? ' is-victim' : ''); if (idx === 0) item.classList.add('active'); item.innerHTML = `
${c.name}
${c.role || ''}
`; item.onclick = () => showScript(c, item); list.appendChild(item); }); if (DATA.characters.length > 0) { showScript(DATA.characters[0], list.firstChild); } } ``` ```javascript if (hasPrivate) { tabsHTML += `
Private script
`; panelsHTML += `
${c.scriptPrivate}
`; } if (hasGoals) { tabsHTML += `
Hidden goals
`; panelsHTML += `
${c.goals}
`; } ``` ### Technical Analysis The data model labels private scripts as visible only to the corresponding player, but the template places every character's private script and hidden goals in one client-side document. It then creates ...[truncated 1365 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
> - 新增 references/visualization-template.html 模板文件

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 422)May include surrounding context.

md
> - 新增 references/visualization-template.html 模板文件

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-tips.md (reported line 1)May include surrounding context.

md
# 剧本杀设计技巧参考手册 v1.4

> 本文件是 AI 生成剧本时的**规范化参考手册**。
> 每条技巧均有固定格式:适用类型 → 设计步骤 → 模板 → 检查清单。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content strongly assumes and enforces Chinese-language interaction without offering language negotiation or fallback behavior. This can create unsafe or confusing operation in multilingual environments, causing user intent to be misunderstood, safety messaging to be inaccessible, or outputs to be unusable when the surrounding system or user is operating in another language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation examples use broad natural-language phrases such as '帮我做个剧本杀' and similarly generic requests, which can cause the skill to trigger in situations where the user did not clearly intend to invoke this specialized workflow. Over-broad activation increases the chance of unintended routing, context hijacking, or suppression of higher-priority assistant behavior because ordinary conversation can be misclassified as a skill invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all template instructions are written entirely in Chinese, presenting the skill behavior as Chinese-only by default. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly requires '本土化' using Chinese-familiar nursery rhymes, Chinese-context death methods, and Chinese settings as a normative design rule. This imposes a specific language/locale and cultural context without any opt-in or alternative path for users who may want non-Chinese localization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction that every generated image 'must include clear Chinese text labels' imposes a fixed language requirement. SQP-3 applies because this is a natural-language locale policy constraint, and the file does not provide user opt-in, language selection, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file instructs the skill to automatically enter a visualization-generation step and create a 素材包/ folder with multiple output files, but it does not warn the user about these file-creation side effects. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that can affect user data or system state, and here the automatic write behavior is explicit but undisclosed as a user-facing caution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title and directive language establish the skill content entirely in Chinese and state it must be followed every time, but there is no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document title and all operational instructions are written exclusively in Chinese, establishing the framework in a single language. There is no indication anywhere in the file that users may choose another language or opt in to Chinese, which can violate language/locale policy when the skill is applied broadly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template loads D3 from a third-party CDN at runtime, which creates a supply-chain and privacy risk for a skill that otherwise appears to be a local visualization artifact. If the CDN, network path, or dependency version is compromised, opening the generated HTML could execute attacker-controlled JavaScript in the user's browser.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The UI explicitly renders scriptPrivate and goals content in the same client-side document as public content, with no access control, redaction, or warning. In the context of a murder-mystery tool, these fields are intended to be secret per player, so exposing them in a shared HTML artifact can spoil the game and leak sensitive role information to anyone who opens or inspects the page.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file is entirely written as prescriptive guidance in Chinese and presents itself as the reference standard for the skill, but it does not indicate that the language is optional or configurable by user preference. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template specifies 姓名:[中文全名,或配合风格的名字], which imposes a Chinese-name default in natural language. Because the file does not provide an explicit user opt-in or broader language/locale choice, this may conflict with a language/locale neutrality policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The host guide explicitly instructs players that they may lie, form alliances, accuse others, and be compelled to answer questions, but it does not include any content warning or safety guidance for emotionally intense, confrontational, or coercive roleplay. In a script intended for novice hosts, this omission can lead to avoidable player distress, social conflict, or unsafe escalation because the facilitator is not prompted to establish boundaries or opt-out mechanisms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file contains the skill guidance exclusively in Chinese, and nowhere indicates that the user can choose another language or that the skill is intentionally limited to Chinese-speaking use. Under the policy rule, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document sets lang="zh-CN", and the interface text throughout the template is written only in Chinese, which enforces a specific language/locale experience. The file does not offer localization choice or explain that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file contains extensive player- and host-facing instructions exclusively in Chinese, with no note that the skill is Chinese-only, region-specific, or that users can choose another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.