Back to skill

Security audit

黑石写作助手·短故事版

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese short-fiction writing skill whose file, cloud, and update behaviors are disclosed and require user confirmation for sensitive actions.

Install this if you want a Chinese-language short-fiction writing assistant. Review prompts carefully before allowing cloud activation, MCP configuration changes, uploads/downloads, auto sync, or self-updates, because those actions can affect account connection, local files, and stored story content.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation text is broad enough to match generic requests for writing short stories or fiction, which can cause unintended skill invocation instead of a more appropriate tool or baseline assistant behavior. While not overtly malicious, this kind of overbroad routing can hijack user intent, increase unnecessary file/cloud handling exposure, and make downstream actions occur in the wrong capability context.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger phrase is short and conversational, making it likely to collide with ordinary user speech and activate the skill when the user did not specifically intend this specialized workflow. In context, the skill has local-file and optional cloud behaviors, so accidental routing is more significant than a harmless content-only misfire.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt is broad enough to match ordinary requests like turning an idea into a short story, which can cause accidental activation of this skill when the user did not explicitly intend to invoke it. In a multi-skill environment, this can route user content into the wrong workflow, increasing the chance of unintended file operations or cloud-related actions described by the skill metadata after activation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file content is entirely in Chinese and does not offer a language fallback or document that the skill is restricted to Chinese-speaking users. This can cause users to misunderstand instructions, consent boundaries, or workflow expectations, especially when the surrounding platform may serve multilingual users.

Static analysis

No suspicious patterns detected.