Back to skill

Security audit

灵造

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its creator-research purpose, but its credentialed online client and mutable update flow create review-worthy security risk.

Install only if you are comfortable using a Chinese creator-operations skill that can call Lingzao's online service with your API key, public links, prompts, and explicitly selected reference images. Use HTTPS for any non-local API endpoint, avoid putting API keys in shell commands, and treat the update command as a trusted-publisher action only after checking the source/version yourself.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/configure.py:65
Finding

Bearer API Key and User-Supplied Images Can Be Transmitted over Plaintext HTTP

Content
View full analysis
dict: api_key = str(config.get("api_key", "")).strip() base_url = str(config.get("base_url", "")).strip().rstrip("/") if not api_key.startswith("lgz_"): raise SystemExit("Invalid Lingzao API key. It should start with lgz_.") if not base_url.startswith(("http://", "https://")): raise SystemExit("Invalid Lingzao base URL. It should start with http:// or https://.") return {"api_key": api_key, "base_url": base_url} ``` ```python # scripts/lingzao_client.py:894-917 def request_json( config: dict, method: str, path: str, body: Optional[Dict[str, Any]] = None, timeout: int = DEFAULT_TIMEOUT, headers: Optional[Dict[str, str]] = None, ) -> Dict[str, Any]: url = config["base_url"] + path data = None request_headers = { "accept": "application/json", "authorization": f"Bearer {config['api_key']}", } if headers: request_headers.update(headers) if body is not None: data = json.dumps(body, ensure_ascii=False).encode("utf-8") request_headers["content-type"] = "application/json" request = urllib.request.Request(url, data=data, headers=request_headers, method=method) try: record_timeout_probe(method, path, timeout) with urllib.request.urlopen(request, timeout=timeout) as response: return parse_json_response(response.read()) ``` ```python # scripts/lingzao_client.py:935-948 def request_multipart( config: dict, method: str, path: str, fields: Dict[s ...[truncated 3951 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:342
Finding

Update Workflow Installs an Unpinned Mutable Package from a Remote Source

Content
View full analysis
dict: local_version = read_local_version() remote_version = None error = None base_url = str(skill_base_url or DEFAULT_SKILL_BASE_URL).strip().rstrip("/") version_url = f"{base_url}/VERSION" try: request = urllib.request.Request( version_url, headers={ "accept": "text/plain", "user-agent": "LingzaoSkill/1.0", }, method="GET", ) with urllib.request.urlopen(request, timeout=timeout) as response: remote_version = response.read().decode("utf-8").strip() except (OSError, UnicodeDecodeError, TimeoutError) as exc: error = str(exc) update_available = ( bool(local_version and remote_version) and compare_versions(remote_version, local_version) > 0 ) return { "ok": error is None, "local_version": local_version, "remote_version": remote_version, "update_available": update_available, "version_url": version_url, "error": error, } ``` ### Technical Analysis The update procedure installs a Skill package from a mutable HTTPS URL. It does not pin an immutable package version, validate a cryptographic checksum, verify a signed manifest, or authenticate individual package fil ...[truncated 2163 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/setup.sh:12
Finding

API Keys Can Be Exposed through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (93)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code does not implement creator research, self-media operations, content querying, writing, image generation, or API-backed functionality described in the skill summary. Instead, it is an internal QA/validation script for a playbook router, operating on local JSON and markdown files to enforce routing consistency rules. This is a materially different primary purpose from the declared end-user skill behavior, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a feature-rich creator research and content-operations skill. However, the provided code only resolves the repository root, reads a local VERSION file, and prints the version string. This is a build/release utility rather than functionality related to topic research, content generation, diagnostics, publishing workflows, public data retrieval, or image generation. While this may be a harmless support script within the project, the supplied code chunk itself does not match the declared purpose and instead serves a materially different purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 327)May include surrounding context.

md
Resolve this `SKILL.md` directory as `<skill_root>`, then run setup once:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

md
Resolve this `SKILL.md` directory as `<skill_root>`, then run setup once:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

md
s not exist, find the directory that contains `lingzao`'s `SKILL.md`, then run `scripts/setup.sh --skip-doctor` from that directory.

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

The skill instructs the agent to fetch a remote URL with curl -L and save the content locally before analysis, without any origin validation, content validation, or checksum/integrity check. Because the URL is returned by an external service, this can expose the agent environment to untrusted remote content retrieval, SSRF-style misuse against accessible endpoints, or downstream processing of malicious files.

Content

Scanner excerpt · SKILL.md (reported line 560)May include surrounding context.

Do not search only inside items[]. If data.artifacts.subtitle_markdown.status == "ready" and url exists, download it before deep script or subtitle analysis:

bash
curl -L "$subtitle_markdown_url" -o /tmp/lingzao-profile-subtitles.md

Use the downloaded Markdown file for complete subtitle/copy analysis. Use --format json when the user needs the structured fields. JSON includes data.artifacts.subtitle_markdown.url for the complete Markdown file when available, and inline items[].text.subtitle.content/plain_text are preview-sized to keep the response readable. If the artifact is unavailable, use the inline subtitle fields. For Douyin, expect data.artifacts.subtitle_markdown.status == "unsupported" and use the returned profile insights plus selected-video extraction instead.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · playbooks/image-generation-agent-integration-guide.md (reported line 72)May include surrounding context.

md
- platform/format or aspect ratio
- visual direction: reference image, color palette, style group, or real
  material
- exact on-image text or a clear statement that Lingzao should choose the text

If the minimum brief is not met, return `next_action: send_reference_or_color`
or a similar friendly state instead of starting generation.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · playbooks/image-generation-execution-workflow.md (reported line 19)May include surrounding context.

md
## Product Principle

Do not expose prompt-only work as the main product experience.

User-facing output should be:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · playbooks/draft-rewrite-and-benchmark-workflow.md (reported line 274)May include surrounding context.

md
## Core Rule

Do not judge a missing draft. First confirm whether the user has finished the
content.

If the user has not sent the content yet, use short wording:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · playbooks/pre-publish-readiness-check.md (reported line 13)May include surrounding context.

md
## Core Rule

Do not judge a missing draft. First confirm whether the user has finished the
content.

If the user has not sent the content yet, use short wording:

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/lingzao_client.py (reported line 775)May include surrounding context.

python
if not prompt.strip():
        raise LingzaoError("generate-image prompt cannot be empty.")
    return prompt


def check_skill_version(skill_base_url: str, timeout: int = DEFAULT_TIMEOUT) -> dict:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to use shell, network, filesystem, environment variables, and local writes, but it does not declare any explicit tool scope or permission boundary. That increases the blast radius of prompt-driven actions because an agent runtime may allow more capability than the user expects, especially given the numerous command examples and file operations in the skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
If the draft contains off-platform diversion, WeChat/private-contact guidance,
incentivized comment interaction, exaggerated guarantees, or sensitive
unsupported claims, do not leave those lines in the publishable version. Show a
short risk note and rewrite them into a safer Xiaohongshu version. Never
promise platform approval; say the rewrite lowers risk.

For commercial or product-related Xiaohongshu outputs, keep the order:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file instructs the agent to use a fixed Chinese response template when a user has installed the skill but has not configured an API key yet. This imposes a specific language/locale on user-facing output without offering a language choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill tells the agent to invoke npx skills without pinning an exact version or integrity-checked source. This creates a supply-chain risk where a newer or compromised package version could change behavior or execute unexpected code during install/update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The update flow again relies on unpinned npx skills, so the same supply-chain exposure applies during repair or reinstall operations. Repeated install guidance increases the chance that an agent executes a mutable external package in a privileged local environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The skill directs the agent to materialize and possibly transform user-provided images into local temporary directories. Even though intended for legitimate processing, this creates data persistence on disk and potential leakage of sensitive user media if temp files are left behind, stored insecurely, or reused across runs.

Content

Scanner excerpt · SKILL.md (reported line 741)May include surrounding context.

md
- Do not proactively convert image formats. If the input image is already png,
  jpeg, or webp and its file size is reasonable, pass it as-is. Do not convert
  png to webp or jpeg just because an example path uses a different extension.
- Only when a reference image is larger than 2 MB, create a smaller copy in the
  temp directory and pass that copy with `--image`. Keep the file extension and
  actual image bytes consistent. If resizing or compression fails, use the
  original supported image file instead of trying another format.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The default_prompt hard-codes Xiaohongshu-specific risk gates and output handling before returning certain content, even when the user may be working on broader or different platforms. This can override user intent, bias the agent's responses toward a locale-specific compliance regime, and create hidden behavior shaping that is not obvious at invocation time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest sets allow_implicit_invocation: true with no visible trigger narrowing, so the skill may be auto-selected in contexts the user did not explicitly request. Because the default_prompt is long, prescriptive, and capable of steering behavior across many creator-operation tasks, broad implicit activation increases the chance of unintended data handling, unwanted policy routing, or action suggestions outside clear user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The version note explicitly says insufficient-credit failures now render 'one concise Chinese recharge instruction'. This is a natural-language locale policy constraint that forces a specific language without any user opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

At L035 the skill uses a Chinese-only user request example ("值不值得学"), and at L052 it further defines activation using Chinese phrases such as "完整分析, 深度拆解, 正式报告, 可视化报告". Because the document does not offer an opt-in language choice or explain that the skill is restricted to a Chinese-language environment, it effectively hard-codes a locale in its natural-language interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains multiple directives and example responses in Chinese, such as 'do口播' and later full Chinese guidance phrases, but it does not state that Chinese output is optional or limited to a China-specific audience. That can violate a language/locale policy when the broader plugin context or user language preference is not explicitly opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs the agent to 'Say:' and then provides required Chinese wording for the response. Because the file does not explicitly let the user choose language or justify a Chinese-only constraint, this is a natural-language locale policy issue rather than just a bilingual example.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The playbook provides required user-facing question wording only in Chinese, and multiple trigger/examples throughout the file assume Chinese-language operation. Because the file does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-language/regional context, it creates a language policy concern under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The playbook activates on very common, high-level user statements such as 'I want to make money' or 'I don’t know what to do,' which creates a broad trigger surface for unsolicited routing into a persuasive workflow. In this skill’s context, that can steer users into a predefined content-production funnel and data-collection sequence even when their request is ambiguous, increasing the risk of overreach and misclassification of user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.