Back to skill

Security audit

中文去 AI 味

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese writing-rewrite skill with clear scope and no code execution, persistence, credential use, or hidden data handling.

Install this if you specifically want Chinese prose checked or rewritten to sound less machine-generated. Be aware that it may activate for broad Chinese pre-publish editing requests, and use care in contexts where preserving formal style, citations, legal wording, or factual precision matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list contains broad, common phrases such as '润色一下读起来自然点' and '发之前帮我过一遍', which can cause the skill to activate in situations beyond narrowly scoped AI-humanization requests. Over-broad activation can redirect normal editing or review tasks into a workflow explicitly designed to alter text so it appears less machine-generated, increasing the chance of unintended policy circumvention or use in deceptive contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The guidance is explicitly framed as normative for Chinese output, such as '中文节奏靠短句', which imposes a language-specific policy on rewriting behavior. The file does not indicate that this constraint is optional, user-selected, or limited to a Chinese-only skill context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title explicitly frames the checklist as Chinese-only ("中文 AI 味清单"), and the document consistently instructs readers using Chinese-specific norms without any opt-in, alternative locale, or scope disclaimer. Because SQP-3 applies to natural-language locale policy, this is a policy concern rather than a content-quality issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language instructions state the skill should be used for Chinese text and is not applicable to English or non-Chinese content. This imposes a language constraint in the skill behavior, but the description does not present it as a user-selectable language option or clearly justified locale-specific compliance limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.