Back to skill

Security audit

中文论文写作

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese academic-writing assistant with disclosed, purpose-aligned read-only audit helpers and clear limits on networking, persistence, and evidence use.

Install this only if you want a Chinese academic-writing workflow. Expect it to read drafts and sources you provide, use its packaged guidance files, optionally run read-only local audit scripts, and use web/source lookup only after you authorize that scope. Do not treat it as a guarantee of institutional compliance or as permission to submit undisclosed generated work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该描述与代码存在明显不匹配。代码的核心目的非常具体且狭窄:对文稿进行只读的 citation audit,检查编号引文、作者年份引文、参考文献编号映射、重复 DOI、疑似未加引文的论断、以及显式引用标记覆盖率阈值等。这属于论文写作流程中的一个辅助质检子工具,而不是描述中所说的“协作完成论文提纲、段落与章节起草、改写和独立审稿”的通用写作/编辑能力。虽然声明中提到“核对证据与引用”,与代码部分重合,但这只是描述中的附属用途,不足以覆盖代码的实际主功能。代码也未实现任何生成、改写、降重、长稿一致性处理或完整审稿能力,只会输出结构化审计结果。因此应判定为描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该描述与代码主功能存在明显不一致。描述强调的是论文写作协作与内容生成/改写/审稿流程;而代码是一个命令行式 prose linter,核心是读取文件后按正则、频率和结构启发式进行风险扫描,并输出 findings。它确实与“独立审稿”中的部分检查有关,但只覆盖很窄的只读候选项报告,且主实现完全不包含提纲生成、段落/章节起草、改写、证据核对或长稿一致性重写等描述中的关键能力。与此同时,代码还具有具体的文件解析、DOCX 提取、JSON 输出、strict 退出码等操作性能力,这些都未在声明中体现。因此这是材料性描述不匹配,而非仅仅实现细节差异。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to read multiple local reference files such as references/*.md, but it does not declare any explicit tool scope or allowed-tools boundary. Undeclared file-read behavior increases the risk of overbroad filesystem access, unexpected data exposure, and review blind spots because operators and users cannot easily see what resources the skill may access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill is for completing Chinese academic writing, which establishes a mandatory language scope in natural language. The file does not present this as an opt-in language preference or offer an alternative, so it can violate the locale/language choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name, description, and default prompt consistently require Chinese academic writing, which imposes a specific language choice in the skill's natural-language behavior. The file does not indicate that the user may select another language or explicitly opt into the locale restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default prompt describes using the skill to complete Chinese academic writing tasks, but it does not define specific trigger phrases, activation boundaries, or exclusion conditions. In a manifest file, this broad invocation wording can make it unclear when the skill should activate versus when ordinary writing-assistance requests should not invoke it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The title explicitly frames the skill as a Chinese literature review specialization, and the file contains no indication that language is optional or user-selectable. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L01-L03 state that this skill is specifically for a Chinese thesis proposal and should only be used when the final deliverable is a Chinese proposal. This imposes a language/locale constraint in natural language, but the file does not indicate user opt-in alternatives or explain a policy-based justification for requiring Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is explicitly scoped to Chinese academic writing and its instructions are written entirely in Simplified Chinese, effectively steering the agent to respond in that language by default without explicit user opt-in. This can override user language preference, reduce accessibility for non-Chinese readers, and create a prompt-priority conflict where the skill constrains output format more than necessary for the task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s natural-language instructions are entirely in Chinese and describe how the reviewer should perform the task, but they do not indicate that language selection is optional or user-driven. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern unless the constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is written fully in Chinese and does not indicate that the user can choose another language or that the skill is intentionally restricted to a Chinese-language context. Under the natural-language policy rules, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This Python file contains natural-language result text in Chinese for duplicate-paragraph findings. Because the skill does not offer a language or locale selection, it imposes a specific language on users, which matches the policy's language/locale violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Several finding-detail strings for LaTeX label/reference issues are emitted only in Chinese. This is a natural-language policy concern because the file enforces one language for user-visible output and does not present an opt-in, language selection, or region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The terminology and abbreviation finding messages are also emitted solely in Chinese. Across the file, this creates a consistent forced-language experience without user choice, which fits the policy's prohibited language/locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.