Back to skill

Security audit

Academic Paper Workflow

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a user-guided academic paper workflow that writes local workflow outputs, but some supporting reference documents are garbled and should be cleaned up.

Before installing, be comfortable with a Chinese-language academic writing workflow that creates local output files. Treat claims like hallucination-free writing as workflow goals rather than guarantees, keep human review for citations and final submission, and ask the publisher to repair the garbled reference documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Hidden Instructions

High
Category
Prompt Injection
Confidence
93% confidence
Finding

The leading BOM/hidden character combined with corrupted text creates a hidden-instruction risk because reviewers and simple scanners may not see the true content as intended. In a security-sensitive agent skill that claims transparency and auditability, invisible or non-rendering characters directly undermine review and can be used to smuggle or obscure instructions.

Content

Scanner excerpt · references/integrity-check-rules.md (reported line 1)May include surrounding context.

md
# 瀛︽湳璇氫俊妫€鏌ヨ鍒欙紙Integrity Check Rules锛?
鏈枃妗e畾涔夊鏈瘹淇℃鏌ョ殑璇︾粏瑙勫垯銆侀獙璇佹柟娉曞拰淇绛栫暐銆?
---

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

The leading hidden character/BOM at the start of the file can conceal content differences, interfere with parsers, and make security review less reliable when combined with already-corrupted text. Hidden or non-printing characters are risky in instruction files because they can cause tools or humans to interpret the document differently than intended.

Content

Scanner excerpt · references/skill-orchestration.md (reported line 1)May include surrounding context.

md
# 鎶€鑳藉崗璋冩寚鍗楋紙Skill Orchestration锛?
鏈枃妗h鏄庡浣曞崗璋?8 涓妧鑳藉崗鍚屽伐浣滐紝閬垮厤鍐茬獊鍜岄噸澶嶅姵鍔ㄣ€?
---

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
# 宸ヤ綔娴佽缁嗛樁娈佃鏄庯紙Workflow Stages Detail锛?
鏈枃妗f彁渚?7 涓樁娈电殑璇︾粏鎿嶄綔鎸囧崡銆佹鏌ユ竻鍗曞拰鏁呴殰鎺掗櫎銆?
---

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/workflow-stages.md (reported line 1)May include surrounding context.

md
# 宸ヤ綔娴佽缁嗛樁娈佃鏄庯紙Workflow Stages Detail锛?
鏈枃妗f彁渚?7 涓樁娈电殑璇︾粏鎿嶄綔鎸囧崡銆佹鏌ユ竻鍗曞拰鏁呴殰鎺掗櫎銆?
---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill orchestrates multiple steps that explicitly reference reading reports, loading journal templates, and generating output files, which implies file read/write capability. Declaring no tool scope or allowed-tools leaves those capabilities undocumented and potentially unrestricted, increasing the chance that an agent can access or modify files beyond the intended workflow boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and document content are presented in Chinese and describe the workflow as if that is the default operating language, but there is no opt-in, multilingual option, or justification that the skill is region-specific. This can violate language/locale policy when users are not given a choice of language.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
95% confidence
Finding

The file content is visibly mojibake/garbled text, indicating an encoding or Unicode normalization problem. In an agent skill, corrupted text can hide the actual instructions from reviewers and cause the model or downstream tooling to misinterpret policy, which reduces auditability and can mask unsafe behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is written entirely in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
94% confidence
Finding

The file content appears mojibaked or encoding-corrupted, producing unreadable mixed-script text. In a skill-orchestration document, this is dangerous because operators and downstream agents may misinterpret workflow constraints, skip required checks, or fail to notice unsafe instructions hidden by encoding issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is written entirely in Chinese and presents all invocation guidance, workflow descriptions, and examples in that language. There is no visible note offering alternative languages or allowing the user to choose their preferred locale, which may violate a language/locale policy requiring user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's user-facing docstring, prompts, and workflow instructions are written entirely in Chinese, and the skill does not offer an English or user-selectable language option. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing natural-language strings entirely in Chinese, including the module description and usage instructions. Under the policy rule for language/locale, forcing a specific language without opt-in can exclude users and is not justified in the file as a region-specific or compliance-bound tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill documentation is presented entirely in Chinese, beginning with the title, and does not indicate that other languages are supported or that Chinese is required for a region-specific reason. This can be a natural-language locale policy issue because it implicitly constrains users to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is written only in Chinese ("学术论文工作流程自动化技能"), which suggests a fixed language presentation without any indication that users can choose their preferred language. The policy requires flagging language or locale constraints unless the skill offers opt-in or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and function descriptions present this script as a validation/checking tool for workflow outputs. In addition to inspecting files, it creates validation_summary.json in the provided output directory, which is a state-changing behavior not conveyed by the stated '检查/验证' purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.