Back to skill

Security audit

大女主小说创作主编

Security checks for vulnerabilities and agentic risk

Overview

This Chinese novel-writing skill is not malicious, but it can read, create, and overwrite local files in under-scoped output directories.

Review before installing. Use it only with a fresh, dedicated output directory, avoid pointing it at folders that contain private or unrelated documents, and back up any existing drafts because the skill can scan prior files and overwrite matching chapter or final-output files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:36
Finding

Hard-Coded Personal Output Directory Enables Unintended File Access and Overwrite

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 36
Vulnerability Type: Unsafe hard-coded filesystem path and insufficient output isolation
Risk Level: Medium

Vulnerable Code Snippet

The following is a faithful English translation of the complete rule at the affected location:

markdown
8. **Output path:** User-specified path → validate it as an absolute path without `..` and ensure it does not point to a system directory → fall back if validation fails. Default path: `/Users/afeng/Documents/侯佳男/华夏基金2026/NLP_Learn/.claude/skills/99-写作(小说、剧本)/95-短篇小说/03-大女主/danuzhu-novel-master/assets/output`.

The continuation workflow later instructs the agent to scan the selected directory, read existing outlines and chapters, and write or overwrite generated Markdown and TXT files there.

Technical Analysis

The Skill uses a developer-specific absolute directory as its default output location whenever the user does not provide another path. This directory is outside the installed project and exposes a personal username and private directory structure.

The path checks only reject relative traversal and a small set of system directories. They do not enforce a trusted output root, resolve and validate symbolic links, verify ownership, or require approval before reading and modifying an existing external directory. Because the continuation workflow treats existing files as prior state, the agent may read unrelated files from that location and incorporate their contents into later model processing.

The Skill also states that intermediate drafts are overwritten rather than versioned. If the hard-coded directory exists and contains files with expected names, generated content can replace those files. The issue does not independently grant operating-system privileges; exploitation is limited to the filesystem permissions already held by the executing agent.

Attack Path

  1. A user invokes the novel-generation S ...[truncated 1556 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the developer-specific absolute path with a project-relative output directory resolved from the installed Skill root.
  2. Define a dedicated allowed output root and reject every path whose canonicalized form falls outside that root.
  3. Resolve symbolic links before authorization checks and repeat validation immediately before file access to reduce link-swap risks.
  4. Require explicit user confirmation before scanning, reading, or modifying an existing directory outside the project workspace.
  5. Use non-destructive, collision-safe filenames by default. Require explicit approval before replacing an existing file.
  6. Write through securely created temporary files and perform an atomic rename only after successful generation.
  7. Create backups or use versioned output files when continuation mode modifies existing work.
  8. Remove personal usernames and private directory structures from distributed configuration and documentation.
  9. Restrict continuation scanning to known extensions and expected file patterns under the validated output root.
  10. Add tests covering path traversal, symbolic links, output collisions, external absolute paths, and failed canonicalization.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README content is written entirely in Chinese and directly instructs the skill to write a novel in that language, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only regional use case. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to write and overwrite files, but the user-facing description does not warn that execution will create, replace, and merge files on disk. That creates a consent and transparency problem: a user may invoke a writing-focused skill expecting text generation only, while the agent performs state-changing filesystem operations that can overwrite prior work.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The continuation logic directs the agent to scan the target directory, inspect existing files, and read prior content to resume work, but this behavior is not surfaced to the user in the skill description. This can expose unrelated or sensitive documents placed in the same directory and expands the skill's data access beyond what a user may reasonably expect from a creative-writing request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file consists entirely of Chinese narrative text and provides no indication that the language choice is optional or limited to a justified region-specific use case. Under the stated policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file says the skill should be referenced '当写作需要强化权谋布局、人际关系博弈、反转设计时参考', which is a general writing condition rather than a specific invocation trigger. It does not define clear boundaries, explicit trigger phrases, or exclusion cases, so the skill could be invoked in a wider range of ordinary writing contexts than intended.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s stated role is formatting text, but it also instructs writing a file to disk and creating directories. Because the output path is supplied by the caller and no scope restriction is defined, the skill can be used to place files in unintended locations, expanding its capabilities beyond pure formatting into filesystem modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly performs filesystem modifications by saving a TXT file and creating directories, but it does not require any warning or confirmation to the user. This creates a safety and transparency gap: users may invoke what appears to be a formatting helper without realizing it can alter local storage state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Allowing a fully caller-controlled output path enables arbitrary file placement, which can overwrite user files, drop content into sensitive directories, or be chained with other components that trust files by location. Even if the content is only a TXT novel, uncontrolled path selection turns a formatting skill into a generic file-write primitive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes a specific narrative language/style and persona ('you are Wang Feng', first-person Chinese colloquial voice) without any explicit user opt-in inside the skill itself. In a multi-skill agent, this can override user preferences or system expectations, causing unwanted outputs, reduced user control, and prompt-steering behavior even when the user only asked for general writing help.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The instructions require the entire novel to use a fixed first-person colloquial style such as '像给闺蜜发语音' and similar culturally specific phrasing, without offering the user a language or style choice. This is a natural-language policy concern because the skill mandates a fixed linguistic register rather than allowing user preference or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This is a plain text file, so SQP-1 applies. The content begins directly with broad second-person narration ("我跟你说件事" / "你听着就行") and provides no explicit invocation criteria, scope limits, or exclusion conditions, which would make activation ambiguous if this text were used as a skill description or trigger source.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file is entirely written in Chinese and does not offer any language or locale choice. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.