Back to skill

Security audit

灵造

Security checks across malware telemetry and agentic risk

Overview

Lingzao is a disclosed creator-research and content-workflow skill that uses a local CLI, a saved API key, paid public-data lookups, and image generation with user confirmation gates.

Install only if you are comfortable configuring a Lingzao API key and sending selected public links, prompts, and any chosen reference images to the configured Lingzao service. Confirm credit budgets before paid lookups or image generation, review outputs before publishing, use a trusted base URL, and choose knowledge-base sync destinations explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (25)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the agent to use shell commands, read and write local files, inspect environment variables, and access external network endpoints, yet no explicit permission model is declared. This creates a broad, implicit trust boundary where an installable skill can perform sensitive actions on the host and user data without transparent scoping or user-visible capability restrictions.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest allows implicit invocation while pairing it with an extremely broad default prompt that authorizes many loosely bounded tasks across research, content generation, compliance checks, budgeting, and external lookups. This increases the chance the agent will invoke the skill in unintended contexts, expose user data or workflow context to the skill unnecessarily, or let the skill steer behavior far beyond a narrowly scoped user request.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The framework instructs the agent to infer and steer recommendations based on gender or identity categories before establishing necessity, user consent, or careful handling of sensitive attributes. In a creator-coaching context, this can lead to profiling, stereotyping, and unequal guidance, especially when the user did not explicitly ask for demographic segmentation. The surrounding skill context makes this more concerning because it operationalizes these categories as a default decision step rather than an optional, narrowly scoped marketing attribute.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation criteria are very broad and include generic situations like starting from zero, wanting to make money, or not knowing what to do. In an agent setting, this can cause the skill to trigger for many loosely related queries, steering users into this workflow even when a narrower or more appropriate skill should handle the request, which can degrade routing quality and increase unintended influence over user decisions.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The keyword tree and surrounding guidance treat women as the default beginner persona, especially around 'female growth' and age-based assumptions, without first confirming user identity or preference. In an agent workflow, this can bias outputs, reduce relevance for other users, and lead to inappropriate profiling or exclusionary recommendations that affect downstream advice quality.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The playbook hard-codes a Chinese user-facing reply template ('不用每次都自己加这句话…') without indicating that the agent should respect the user's language preference. This can cause the agent to ignore or override the language used by the user, degrading usability and potentially causing misunderstandings in multilingual contexts, but it is not a direct security compromise.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
These lines prescribe fixed Chinese wording for user-visible output, again without offering language selection. A rigid language constraint can make the agent produce inaccessible or confusing responses for non-Chinese users, which is a product quality and instruction-priority issue rather than a high-severity security flaw.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The 'ordinary users' reply template is explicitly fixed in Chinese, which can force output language regardless of the user's preference. In skill behavior, this is a genuine vulnerability in the sense of reduced user control and possible miscommunication, but the surrounding content is operational guidance for benchmark-account discovery, so the danger is limited to accessibility and trust rather than data exposure or code execution.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The playbook hard-defaults output to Chinese-language Xiaohongshu content and repeatedly instructs the agent to proceed with that platform/format unless the user corrects it. In a multi-platform, multilingual agent context, this can override user intent, cause cross-context prompt steering, and lead to inappropriate disclosure or posting preparation for the wrong audience or platform without explicit opt-in.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The playbook activates on broad colloquial phrases such as '帮我过一遍' and '发之前检查', which can appear in ordinary conversation without the user clearly requesting this specific pre-publish workflow. In an agent setting, overly broad triggers can cause unintended skill invocation, leading the agent to steer the conversation into publication-review behavior and potentially request draft content or apply platform-specific guidance when that was not the user's intent.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The playbook activation text is broad enough to match generic product-discussion requests, so the skill may trigger outside its intended scope and steer conversations into Lingzao-specific workflows without clear user intent. In an agent setting, overbroad routing increases the risk of incorrect tool/playbook selection, irrelevant guidance, and unintended handling of user inputs that should have been processed by a different skill or by the base assistant.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The listed trigger phrases are short and ambiguous, and many can appear in ordinary conversation unrelated to this skill. That makes accidental invocation more likely, which can cause the agent to misclassify user intent, apply the wrong workflow, and produce product/marketing-oriented responses when the user wanted general advice or a different capability.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are very broad and conversational, so the workflow may activate on loosely related requests and steer the agent into a prescriptive content-production flow without clear user intent confirmation. In an agent setting, overbroad activation can cause inappropriate routing, irrelevant prompts for uploads/links, and unintended handling of user content or external references.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The workflow hardcodes a Chinese-language prompt without checking the user's preferred language, which can override user expectations and reduce transparency about what the agent is doing. In multilingual agent environments, forced language can cause confusion, misinterpretation of consent when requesting images/links, and accidental exclusion of users who cannot properly review the generated guidance.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The playbook hard-codes Chinese-language interaction patterns and example responses without indicating that the assistant should adapt to the user's preferred language. This can override user expectations, reduce transparency, and create unsafe or inaccessible interactions if users cannot understand the guidance, consent prompts, or scope reminders being given.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The router uses short, generic Chinese phrases such as “不知道”, “草稿”, “100 字”, and “直接生成” as routing signals, which can easily appear in unrelated user requests. In an agent skill, ambiguous triggers can cause unintended playbook selection, leading the agent to invoke workflows that access paid APIs, generate content, or process external resources without clear user intent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The route signals are intentionally written in broad natural language, which can cause the router to select a playbook for ambiguous everyday requests that only partially match the user's intent. In an agent setting, misrouting can trigger unnecessary workflow loading, paid-scope prompts, or compliance/publishing logic that changes behavior without clear user consent.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The post-publish review route includes vague phrases like reviewing data or adjusting the next post, which can overlap with ordinary analytics or advice requests. This creates a real routing-risk issue because an agent may infer a published-content workflow when the user is only asking a general question, leading to incorrect assumptions about available data and next actions.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The onboarding signals are highly generic and likely to match common exploratory questions from many users, not just true beginner-onboarding scenarios. In a routing manifest, this can steer users into a prescriptive onboarding flow that is misaligned with their actual goal and may crowd out more specific playbooks.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The distribution and prompting routes use broad phrases such as asking how to ask the tool or how to distribute content, which are common forms of normal assistance requests. In an agent environment, overly permissive triggers can hijack general conversations into specialized workflows, causing unintended prompt shaping or multi-platform planning behavior.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The template instructs the agent to offer knowledge-base synchronization and prepare exportable Markdown containing user report content and links, but it does not require a clear privacy warning or explicit confirmation of what data will be exported before that step. In an agent environment with connected tools, this can lead to unintended disclosure of sensitive user-provided materials, account analysis, or private links into third-party knowledge systems.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad phrases such as '整理这一周内容', '下周发什么', and '帮我做 5 个母题', which can plausibly appear in ordinary planning conversations outside the intended workflow. This can cause unintended activation of the playbook, leading the agent to apply the wrong workflow, request unnecessary materials, or generate content-planning outputs when the user wanted a simpler response.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase “我想赚钱但不知道做什么账号” is broad and can match many generic money-making requests that are not specifically about onboarding to self-media or Xiaohongshu. In an agent setting, this can misroute users into this playbook unexpectedly, causing irrelevant guidance, reduced reliability, and possible premature steering into creator-business workflows.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The playbook hardcodes Chinese user-facing output without checking the user's language preference or documenting that the skill is Chinese-only. This can cause incorrect or inaccessible responses for users interacting in other languages, leading to confusion and degraded agent behavior, though it is not a direct security exploit.

Session Persistence

Medium
Category
Rogue Agent
Content
- Do not proactively convert image formats. If the input image is already png,
  jpeg, or webp and its file size is reasonable, pass it as-is. Do not convert
  png to webp or jpeg just because an example path uses a different extension.
- Only when a reference image is larger than 2 MB, create a smaller copy in the
  temp directory and pass that copy with `--image`. Keep the file extension and
  actual image bytes consistent. If resizing or compression fails, use the
  original supported image file instead of trying another format.
Confidence
87% confidence
Finding
create a smaller copy in the temp directory and pass that copy with `--image`. Keep the file extension and actual image bytes consistent. If resizing or compression fails, use the original suppo

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.