T02 · Agent Memory Poisoning
- Location
references/professional-analysis-framework.md:425- Finding
Persistent poisoning of the Skill analysis cache
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent murder-mystery generator, but it asks the agent to persist generated analysis into trusted skill reference files and produces a shared HTML visualization that can expose private player material and execute unsafe page content.
Install only after reviewing the persistence and HTML-output behavior. Do not allow the skill to modify its own reference markdown as a cache, treat generated visualizations as host-only unless private fields are removed, and avoid opening or sharing generated HTML that contains untrusted text until the template escapes dynamic content and vendors or pins D3 with integrity checks.
references/professional-analysis-framework.md:425Persistent poisoning of the Skill analysis cache
references/visualization-template.html:349DOM-based HTML and JavaScript injection in generated visualizations
references/visualization-template.html:7Unpinned remote executable dependency without integrity verification
references/visualization-template.html:202Private player scripts and hidden goals exposed in a shared HTML document
Referenced artifact was not completely inspected
> - 新增 references/visualization-template.html 模板文件
Referenced artifact was not completely inspected
> - 新增 references/visualization-template.html 模板文件
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# 剧本杀设计技巧参考手册 v1.4
> 本文件是 AI 生成剧本时的**规范化参考手册**。
> 每条技巧均有固定格式:适用类型 → 设计步骤 → 模板 → 检查清单。
The skill content strongly assumes and enforces Chinese-language interaction without offering language negotiation or fallback behavior. This can create unsafe or confusing operation in multilingual environments, causing user intent to be misunderstood, safety messaging to be inaccessible, or outputs to be unusable when the surrounding system or user is operating in another language.
The activation examples use broad natural-language phrases such as '帮我做个剧本杀' and similarly generic requests, which can cause the skill to trigger in situations where the user did not clearly intend to invoke this specialized workflow. Over-broad activation increases the chance of unintended routing, context hijacking, or suppression of higher-priority assistant behavior because ordinary conversation can be misclassified as a skill invocation.
The file title and all template instructions are written entirely in Chinese, presenting the skill behavior as Chinese-only by default. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.
The document explicitly requires '本土化' using Chinese-familiar nursery rhymes, Chinese-context death methods, and Chinese settings as a normative design rule. This imposes a specific language/locale and cultural context without any opt-in or alternative path for users who may want non-Chinese localization.
The instruction that every generated image 'must include clear Chinese text labels' imposes a fixed language requirement. SQP-3 applies because this is a natural-language locale policy constraint, and the file does not provide user opt-in, language selection, or a documented region-specific justification.
This markdown file instructs the skill to automatically enter a visualization-generation step and create a 素材包/ folder with multiple output files, but it does not warn the user about these file-creation side effects. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that can affect user data or system state, and here the automatic write behavior is explicit but undisclosed as a user-facing caution.
The title and directive language establish the skill content entirely in Chinese and state it must be followed every time, but there is no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.
The document title and all operational instructions are written exclusively in Chinese, establishing the framework in a single language. There is no indication anywhere in the file that users may choose another language or opt in to Chinese, which can violate language/locale policy when the skill is applied broadly.
The template loads D3 from a third-party CDN at runtime, which creates a supply-chain and privacy risk for a skill that otherwise appears to be a local visualization artifact. If the CDN, network path, or dependency version is compromised, opening the generated HTML could execute attacker-controlled JavaScript in the user's browser.
The UI explicitly renders scriptPrivate and goals content in the same client-side document as public content, with no access control, redaction, or warning. In the context of a murder-mystery tool, these fields are intended to be secret per player, so exposing them in a shared HTML artifact can spoil the game and leak sensitive role information to anyone who opens or inspects the page.
The file is entirely written as prescriptive guidance in Chinese and presents itself as the reference standard for the skill, but it does not indicate that the language is optional or configurable by user preference. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.
The template specifies 姓名:[中文全名,或配合风格的名字], which imposes a Chinese-name default in natural language. Because the file does not provide an explicit user opt-in or broader language/locale choice, this may conflict with a language/locale neutrality policy.
The host guide explicitly instructs players that they may lie, form alliances, accuse others, and be compelled to answer questions, but it does not include any content warning or safety guidance for emotionally intense, confrontational, or coercive roleplay. In a script intended for novice hosts, this omission can lead to avoidable player distress, social conflict, or unsafe escalation because the facilitator is not prompted to establish boundaries or opt-out mechanisms.
This markdown file contains the skill guidance exclusively in Chinese, and nowhere indicates that the user can choose another language or that the skill is intentionally limited to Chinese-speaking use. Under the policy rule, forcing a specific language without opt-in is a natural-language locale violation.
The document sets lang="zh-CN", and the interface text throughout the template is written only in Chinese, which enforces a specific language/locale experience. The file does not offer localization choice or explain that the skill is intentionally limited to a Chinese-only regional context.
SQP-3 applies to all file types and includes language or locale policy violations. This markdown file contains extensive player- and host-facing instructions exclusively in Chinese, with no note that the skill is Chinese-only, region-specific, or that users can choose another language.
No suspicious patterns detected.