Back to skill

Security audit

Novel Craft

Security checks for vulnerabilities and agentic risk

Overview

This writing skill is not clearly malicious, but it can automatically search the web and rewrite project files, so it needs review before installation.

Install only if you want a Chinese-language novel workflow that may create and update many project files, automatically rewrite affected chapter text, and perform web research after genre or style selection. Use version control or backups, review diffs after ripple operations, and prefer disabling or manually approving auto_ripple and web research where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims the assistant should not write the novel, yet later defines a chapter generator and ripple engine that automatically generate and rewrite chapter content. This mismatch can mislead users about the scope of autonomous content creation and cause unexpected destructive edits across project files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description highlights automatic ripple rewriting but does not clearly warn that one outline or setting change can trigger multi-file chapter rewrites. In a content-authoring environment, undisclosed cascading edits create a material risk of unexpected data loss, overwrites, or large-scale modifications the user did not intend to authorize.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad phrases like '继续写' or '修改了XX', which can match ordinary conversation and unintentionally activate file-changing workflows. In a skill that can rewrite chapters and alter project state, ambiguous activation raises the chance of unintended autonomous actions and data modification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The mandatory workflow automatically performs WebSearch and WebFetch, then persists extracted techniques into project files, even though the advertised purpose is local novel planning and consistency support. This expands the trust boundary to external content sources, creating privacy, prompt-injection, copyright, and unwanted data-ingestion risks without clear necessity or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description does not warn users that it will automatically search the web, fetch external articles, extract techniques, and write results into project files. Missing disclosure undermines informed consent and can lead to unexpected network access, ingestion of untrusted material, and persistence of externally derived content in the user's workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file contains natural-language documentation and examples exclusively in Chinese, but there is no indication that the user selected Chinese or that the skill is limited to a Chinese-language context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The schema comments, field guidance, enumerated values, and usage instructions are entirely in Chinese, including content expectations such as genre and tone values. Because the file provides no indication that the skill is region-specific or that users may opt into another language, it appears to impose a specific language/locale by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template explicitly supports automatic rewriting of chapter content (auto_rewrite: true) and backup/rollback behavior, but it does not require an explicit user-facing confirmation or warning before modifying user-authored files. In a writing assistant that operates across many chapters and sessions, this can lead to unintended bulk edits, silent content corruption, or user surprise if the mechanism is invoked without clear consent at execution time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file's headings, field descriptions, examples, and instructions are all presented in Chinese, which effectively imposes a specific language on users. The policy allows locale constraints only when users are given a choice or when the restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is entirely framed as a Chinese writing-style guide and states that generation and rewriting must preserve that style, which effectively imposes a specific language/locale expectation. Under the policy rule, language constraints should either be optional for the user or clearly documented as a justified region- or language-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This template and guidance are presented only in Chinese, which can constitute a language/locale policy issue when no user opt-in or alternative language option is provided. The file does not indicate that it is intentionally limited to a Chinese-language audience or region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This YAML reference file uses Chinese exclusively in headings, field comments, examples, and operational instructions. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.