Back to skill

Security audit

Prompt Generator Pack

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language prompt-template pack with no code execution, credential access, persistence, or hidden data handling.

Install this if you want Chinese prompt templates for common writing and marketing tasks. Be aware that its invocation examples are generic, so an auto-router may select it for ordinary prompt-writing requests, and non-Chinese users may find the templates less useful.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation examples are generic requests such as writing copy or generating prompts, which substantially overlap with ordinary user intent and provide no clear activation boundaries. In systems that auto-route or suggest skills based on matching phrases, this can cause unintended skill selection, prompt hijacking of normal tasks, or over-broad interception of user requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description and all user-facing instructions are written in Chinese, and the examples imply the skill is operated in Chinese without stating that other languages are supported. This can violate language/locale policy when no user choice or explicit language constraint is documented.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation guidance is very broad: phrases like “用 xxx 模板” or “给我一个 xxx Prompt” can overlap with ordinary conversation and may trigger the skill when the user did not clearly intend to invoke it. This increases the chance of unintended activation, causing confusing behavior, context switching, or accidental use of the skill in unrelated chats.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Natural-language policy issues include forcing a specific language without user opt-in. This file presents all user-facing instructions in Chinese and does not indicate that the skill is region-specific or provide an alternative language option, which can amount to an implicit language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all prompts and instructions exclusively in Chinese, which can be interpreted as forcing a specific language without user opt-in. The policy for SQP-3 applies to natural-language content in all file types and specifically calls out language or locale constraints when no choice is offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file is entirely framed as Chinese writing prompt templates and repeatedly instructs Chinese-language styles and China-specific platforms, while not offering the user any language or locale opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.