Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
声明描述的是一个覆盖公文与新闻稿件全流程处理的综合写作技能,重点在内容生成、改写、润色、审校和格式处理。实际代码却主要执行长度测量、范围校验、试写标识检查,并可选输出扫描结果。虽然这与“审校”有弱相关,但远不足以支持声明中大量核心能力,且代码的主用途明显是草稿长度与规则合规检查。因此描述与行为存在显著不匹配。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Chinese official-writing skill with local text-checking helpers and bounded research guidance, not a hidden or deceptive package.
Install this for Chinese official-document and formal-work writing workflows. Review outputs carefully before formal use, especially facts, policy citations, dates, official formatting, and any web-sourced material. If you use it with sensitive internal drafts, remember the local scripts read the files you point them at, and web research should avoid sending unnecessary private context.
声明描述的是一个覆盖公文与新闻稿件全流程处理的综合写作技能,重点在内容生成、改写、润色、审校和格式处理。实际代码却主要执行长度测量、范围校验、试写标识检查,并可选输出扫描结果。虽然这与“审校”有弱相关,但远不足以支持声明中大量核心能力,且代码的主用途明显是草稿长度与规则合规检查。因此描述与行为存在显著不匹配。
声明描述的是一个广泛的中文公文/新闻文本智能写作与编辑能力集合,且提到 Word 格式处理;但代码并没有任何自然语言生成、改写优化、审校或格式处理逻辑。其核心是:读取原稿和 JSON 编辑计划,验证 source_sha256,按 old/new/start 执行精确替换,或将候选稿与根据计划生成的预期文本做一致性比对,并输出 JSON 报告。这是一个受限的文本替换范围校验/生成工具,能力边界明显窄于且不同于声明,因此属于实质性描述与行为不匹配。
声明描述的是一个面向中文公文与新闻材料处理的综合写作/编辑工具,能力范围非常广,重点在生成、修改、审校与格式处理。代码却只实现了一个非常具体的比对辅助功能:从两个纯文本文件中定位指定 literal 的出现位置,并输出 JSON 报告,还明确说明“不作事实判断”。这与声明的主要目的存在实质性差异。虽然“审校”场景可能宽泛地包含查找片段,但这里的实际功能过于狭窄且不同,且仅支持 TXT/MD,不涉及 Word,也没有任何起草、改写、润色等实现。因此应判定为描述与行为不匹配。
该描述把技能表述为综合写作与文稿处理助手,核心能力包括生成、重写、压缩、润色、审校和格式处理;而代码的设计目标和实现行为明显更窄,主要是‘检测正式稿件中的风险并报告 finding’。脚本注释还明确写明‘只报告风险,不自动改写正文’。虽然代码确实涉及去口语化、AI 痕迹、部分格式问题、占位符和交付说明残留等,与声明中的部分“审校/降 AI 味/格式检查”方向一致,但它缺少声明中最核心、最广泛的写作生成与改写处理能力。因此属于描述显著大于实际行为、主用途存在偏差的情况。
The title and opening description define the skill exclusively for Chinese official-document writing and provide no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill states that it handles Chinese official and formal materials, and explicitly routes English content elsewhere. This imposes a language constraint in the skill's natural-language policy without presenting a user choice, opt-in, or documented region-specific justification.
The skill explicitly instructs the agent to perform internet research when facing unfamiliar document types or current-policy questions, which expands the data boundary beyond the local writing/editing task. This can introduce prompt-injection exposure from untrusted web content, accidental reliance on malicious or low-integrity sources, and unnecessary disclosure of user task context to external services.
Line L03 instructs the skill to operate "在已选主文种中" (in the already selected primary language), which imposes a language constraint in the skill guidance. The file does not indicate that the user can choose or opt into that language/locale behavior within this skill file, so it constitutes a natural-language language-policy concern.
The title and content specify a Chinese-language writing/checking workflow (e.g. '语言与抗 AI 味检查') and all instructions are written to enforce that language context, but the file does not offer an opt-in or alternative language choice. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.
The entire skill guidance is written in Chinese and frames the writing instructions exclusively in that language, with no indication that users may choose another language or that the skill is limited to a Chinese-language context. Under the policy, language-specific behavior without opt-in or clear justification can be a natural-language policy violation.
The entire routing guidance is written only in Chinese and specifies document-routing behavior for Chinese government-style genres without any indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file uses only Chinese for the skill instructions and does not indicate that the skill is region-specific or that users may opt into another language. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation.
This file’s instructional content is entirely in Chinese, and there is no natural-language indication that the user can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a policy violation.
The entire skill guidance is written as prescriptive instructions for drafting official text in Chinese, including required Chinese forms of address and closing formulas, but it does not state that language choice depends on user preference or context. This can violate a language/locale policy when the skill is invoked in situations where the user has not opted into Chinese-only output.
The file is entirely framed as guidance for producing Chinese official-document formulaic language, and it does not indicate that language selection is optional or user-driven. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.
The entire skill guidance is written as a Chinese-only workflow for reviewing feasibility reports, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.
The entire skill file is written in Chinese and provides no indication that language selection is optional or that the skill is intentionally restricted to Chinese-language users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that the skill is optional for Chinese-language contexts only or that users can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown playbook presents all instructions in a single language and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
The entire skill file is written as a Chinese-only template and provides no indication that language choice is optional or limited to a justified Chinese-language context. Under the policy, a skill that effectively mandates a specific language without opt-in is a natural-language policy violation.
The file presents all instructions exclusively in Chinese and does not indicate that the skill is intended only for Chinese-speaking users or a China-specific workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
The file is entirely written as prescriptive guidance for drafting official correspondence in Chinese, including fixed Chinese phrasing and terminology, with no indication that the user may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.
The entire skill file is written as Chinese-only guidance for producing deployment-style documents, with no indication that users may choose another language or that the skill is restricted to a Chinese-language or region-specific workflow. This creates a natural-language policy risk because it implicitly enforces a specific language without user opt-in.
This markdown file contains all user-facing guidance in Chinese and does not mention any option for other languages or an explicit justification for the locale constraint. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
No suspicious patterns detected.