Back to skill

Security audit

Writing Assistant Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language writing assistant skill with disclosed writing, rewriting, headline, and ideation behavior, and I found no hidden network, credential, destructive, or privileged actions.

Install this if you want a Chinese-first writing assistant for content drafting and optimization. Be aware that it may respond aggressively to broad Chinese writing words and it describes learning writing preferences across sessions, so review or clear its memory files if you do not want those preferences retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill declares itself 'always active', which makes it apply outside clearly scoped writing tasks and can override or interfere with other agent behaviors. Unbounded activation increases the chance of prompt collisions, instruction persistence, and unintended execution in contexts where this persona is irrelevant, reducing predictability and safety.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description, commands, roles, and usage instructions are entirely presented in Chinese, and the example interactions assume Chinese-only use. There is no indication that users may choose another language or that the Chinese locale restriction is an intentional, justified constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example invocations show natural phrases like "改一下这段" and "给这篇文章起10个标题" but do not explain whether these are exact triggers, examples only, or how similar phrasing is handled. Without explicit boundaries, the skill's activation criteria remain unclear and may cause unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented trigger words are single common terms like "写", "改", "标题", and "选题", which are generic words frequently used in ordinary conversation. The README does not provide scope limits, exclusion conditions, or negative examples to clarify when these words should or should not activate the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are extremely generic conversational patterns such as '写一篇...', '改一下...', '标题...', and '选题...'. Because they overlap with common user speech, the skill may activate unintentionally and hijack normal conversations, causing misrouting of user requests and execution of the wrong agent behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is entirely written in Chinese and presents the skill's core identity and operating principles without offering any language choice or documenting that the skill is intentionally region-specific. This can constitute a language/locale policy violation because it implicitly constrains interaction to a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation commands are generic single words like "写", "改", "选题", and "停止", which can easily appear in ordinary conversation and unintentionally switch the agent into a different operating mode. This creates prompt-state confusion and can cause unauthorized or accidental behavior changes without explicit user intent, especially in multilingual or terse chat contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

整个技能记忆文档以中文撰写并围绕中文平台与中文触发词组织,未说明是否仅适用于中文用户,也未提供语言/locale 选择。根据规则,若技能隐含强制特定语言而没有用户 opt-in,属于自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger words are extremely broad single-character/common terms like "写", "改", and "标题", which are likely to appear in ordinary conversation. In an agent skill system, this can cause unintended skill activation, unexpected behavior, or routing of user input into content-generation workflows without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill state document is written in Chinese and presents the shared context exclusively in that language, with no indication that the user can choose another language or that the skill is region-specific. This creates a natural-language locale policy concern because it implicitly enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation descriptions list example phrases for multiple agents but do not define hard trigger constraints, disambiguation rules, or negative examples. In a multi-agent writing assistant, this ambiguity can cause accidental activation, capability confusion, or unintended handling of user content by the wrong agent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rewrite agent trigger is defined as a very common phrase, '改一下这段...', which can easily appear in normal conversation and be interpreted as an invocation when the user did not intend to call the agent. This creates ambiguous activation boundaries and increases the risk of unintended agent execution or routing to the wrong capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The write agent is triggered by the single common verb "写", which is overly broad and likely to appear in ordinary conversation unrelated to explicit agent invocation. This can cause unintended agent activation, misrouting of user requests, or prompt/skill steering when benign text accidentally matches the trigger.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The rewrite agent trigger uses the ambiguous term "改", which is a very common word and can match many unrelated user utterances. This increases the risk of accidental activation, incorrect task routing, and unintended processing of content under the wrong agent path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The ideation agent trigger includes broad phrasing like requests for '创意', which can overlap with many ordinary interactions and broad brainstorming prompts. In a multi-agent environment, this ambiguity can cause accidental dispatch, agent conflict, or attacker-crafted phrasing that nudges execution toward the wrong workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is entirely in Chinese and provides no language selection, fallback, or documented locale restriction. In a multi-operator or multi-agent environment, this can cause reviewers or downstream agents to miss operational instructions, misunderstand self-modification or escalation behavior, and fail to spot unsafe logic embedded in the workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script presents its startup messages and user invocation examples entirely in Chinese, including the expected trigger phrases like "说"写..."" and "说"改..."". That creates a language/locale constraint in natural-language behavior without documenting a user choice or opt-in, which fits the policy-violation criteria for forced language usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and usage examples are presented exclusively in Chinese, which effectively forces a specific language for interaction. The file does not mention any user language choice, opt-in, or justification that this is a region-specific or Chinese-only skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents the skill's persona, communication protocol, and activation instructions exclusively in Chinese, which can amount to a language policy constraint if applied to all users by default. There is no natural-language indication that the user may choose another language or that the locale is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file uses Chinese throughout for task instructions, recommendations, and next-step actions, but it does not indicate that the skill is region-specific or that users can opt into another language. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing skill content exclusively in Chinese, including headings, instructions, and output text. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The headline agent is activated by a loosely defined condition like 'need title creation or A/B testing,' which lacks precise boundaries for when dispatch should occur. While less risky than single-word triggers, underspecified activation can still lead to mistaken routing and unreliable behavior in mixed-purpose requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's natural-language comments and all user-facing output are in Chinese, with no indication that the language is optional or that the skill is intentionally limited to a Chinese-speaking audience. That creates a language/locale policy concern under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.