Back to skill

Security audit

热点爆款写作助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese social-media article workflow that uses web research, local reference docs, a local text checker, and optional cover generation without signs of hidden persistence or data theft.

Install this if you want a Chinese-language workflow for generating and optimizing social-media articles. Before using it, be explicit about platform, article count, whether web research is allowed, and whether cover images should be skipped to avoid unexpected extra output or image-generation cost.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to read local reference files such as references/core_workflow.md, but it does not declare any corresponding tool scope or file-read permission boundary. This creates an authorization mismatch: an agent/runtime may still attempt local file access implicitly, which can lead to unintended access to adjacent files, hidden prompts, or sensitive workspace content if path handling or policy enforcement is weak.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description, title, examples, platforms, and all operating instructions are written exclusively in Chinese and oriented to Chinese-language platforms, but the file does not explicitly state that the skill is Chinese-only or provide a language/locale opt-in. This creates a natural-language locale policy concern because the skill effectively imposes a specific language context without user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions are broad enough that ordinary requests like providing a topic and asking for content generation could invoke the skill without clear user intent to use this specific workflow. In an agent environment, this can cause unintended web searching, bulk content generation, and downstream actions that the user did not explicitly request, increasing the risk of surprise behavior and misuse of tools.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Phrases like '生成今日热点文章' or '追热点' are still relatively vague and may match casual brainstorming requests, causing the skill to launch full hot-topic collection and analysis automatically. Because this workflow includes broad web collection and multi-article generation, accidental invocation can lead to unnecessary external access and output the user did not intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file declares a 'mandatory rule' for Xiaohongshu titles of '≤20字(中文)', which prescribes a specific language/locale in natural-language instructions. The document does not provide user opt-in, alternatives, or a clear justification that the skill is strictly limited to a Chinese-only regional compliance context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow says cover images may be generated automatically based on inferred intent, without clearly warning the user or requiring consent. Automatic media generation is a meaningful side effect: it can consume resources, create unexpected outputs, and potentially produce misleading or policy-sensitive imagery without the user's awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all guidance, prompts, and checklists exclusively in Chinese, beginning with the title and continuing throughout the document. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all operational guidance are written exclusively in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese from start to finish. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, beginning with the title on L0001, and nowhere indicates that the skill is China-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing instructions and examples exclusively in Chinese, and it does not indicate that the skill is region-specific or that users may choose another language. That can violate a language/locale policy requiring user opt-in or documented justification for a forced locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The optimization trigger is defined broadly as the user providing an article and asking to optimize it or check/fix quality. The description lacks boundaries on what counts as eligible input, whether partial text qualifies, or when the workflow should refrain from automatic optimization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions, headings, and examples exclusively in Chinese, which can amount to a language/locale constraint for users who have not opted into that language. The policy allows fixed-language behavior only when user choice or a clear justified regional scope is provided, neither of which appears in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing report strings are written only in Chinese, indicating the skill is designed to operate in a single language with no visible opt-in or fallback. Under the policy, forcing a specific language without user choice is a natural-language locale violation unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.