Back to skill

Security audit

大女主小说创作主编

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed creative-writing workflow that creates and formats local novel files, with no hidden code execution, credential access, or data export found.

Install this only if you want a highly opinionated Chinese 大女主 fiction generator. Expect it to create or overwrite chapter and final-output files in its selected output directory, and expect the heroine, point of view, and voice to default strongly to 王枫 unless the skill is edited.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill hard-codes a specific protagonist identity ('王枫') for what is described as a general narrative-writing subskill. This can override user intent, narrow outputs unexpectedly, and cause the parent skill to generate content with an unintended fixed character/persona, which is a scope-control and instruction-integrity problem rather than a memory-safety issue.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The requirement that every chapter be at least 3000 characters conflicts with the parent skill's stated default of short-form output unless the user specifies length. This can force excessive generation, ignore user constraints, and degrade system compliance by making a subskill override higher-level orchestration rules.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill imposes a fixed language/style profile without explicit user opt-in, which can cause unauthorized tone, language, or narrative-format switching. In agent systems, this is dangerous because a subskill can silently steer outputs away from the user's requested style or the parent skill's broader responsibilities.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The instructions force the model to adopt a fixed Chinese persona and speech mode ('你就是王枫') without user choice. This is a genuine prompt-scope vulnerability because it can hijack output behavior, suppress alternative requested voices, and create misleading identity assumptions in downstream content generation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.