Back to skill

Security audit

AI短剧/漫剧创作大师

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese short-drama and AI-manga writing assistant with purpose-aligned templates and JSON export behavior, and I found no hidden execution, credential access, persistence, or exfiltration behavior.

Install this if you want a Chinese-language short-drama or AI-manga writing workflow with ViFlow-style JSON export. Be aware that it may create generated JSON files under assets/output and its market/platform claims should be treated as creative guidance rather than verified current business data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is very broad and can match ordinary creative-writing requests, causing the skill to trigger in contexts where the user did not explicitly ask for this specialized workflow. Over-broad activation increases the chance of unwanted instruction injection into unrelated tasks and may push file-writing/export behavior without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger section says the skill should activate whenever users mention broad categories like script creation or ViFlow import, but it does not define boundaries or opt-out conditions. This can lead to unintended activation on ambiguous prompts, increasing the risk of surprising behavior and unauthorized workflow steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to export a JSON file to a repository path, but it does not warn the user that a file will be created. Silent file creation is risky because it can modify the workspace unexpectedly, create persistence artifacts, and violate user expectations about whether the interaction is read-only or write-capable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The mandatory export rule makes file output a required side effect while omitting any disclosure or confirmation step. In agent environments, mandatory undisclosed writes are dangerous because they can alter project state, overwrite existing files, or create files the user did not intend to persist.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON file is a manifest/config-type file, so natural-language policy checks apply. Multiple user-facing example values and field guidance are presented only in Chinese, and there is no indication that the schema is intentionally region-specific or that users may choose another language, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest-style JSON is entirely authored in Chinese, including title, audience, episode metadata, prompts, and hook instructions, which indicates a fixed language/locale for the skill output. There is no accompanying field or note offering language selection, opt-in, or a documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents the skill content exclusively in Chinese, and there is no natural-language indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy rule, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown skill file presents all natural-language content in a single language and does not indicate that Chinese is optional, user-selected, or required for a justified region-specific use case. That creates a language/locale policy concern under the rule for natural-language policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This file forces a single language throughout the skill content and does not offer an opt-in, alternative language, or any explanation that it is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely written as a Chinese-language script example and provides no indication that language choice is optional or limited to a justified region-specific use case. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document is written entirely in Chinese and uses prescriptive language such as '必须' for how outputs should be structured, but it does not indicate that language choice is optional or limited to a justified region-specific use case. This can constitute a locale/language policy issue because the skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions and templates exclusively in Chinese, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-language audience. Under the language/locale policy rule, forcing a single language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all guidance exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language, which may violate an organizational policy requiring language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The schema requires imagePrompt to be in English, which imposes a language constraint on the skill's output. Because the document does not present this as optional, user-selected, or technically justified, it conflicts with the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The schema specifies videoPrompt as an English prompt, which is a fixed language requirement embedded in the skill instructions. The file does not offer a language choice or explain that this is required by a specific platform, so it appears to force a locale/language convention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is entirely framed as a Chinese script example, including all headings, dialogue, and generation guidance, with no indication that other languages are supported or that the language choice is optional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains natural-language content exclusively in Chinese and does not mention any supported language options or user selection. Under the language/locale policy category, forcing a specific language without opt-in can be a policy violation when no justification or choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.