Back to skill

Security audit

盗墓小说创作主编

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed creative-writing workflow that generates and saves novel files, with no hidden code, credential access, remote payloads, or persistence found.

Install this only if you want an autonomous Chinese-language tomb-adventure novel generator. Use a dedicated output directory and expect it to create manuscript, review, and final TXT files there without asking many follow-up questions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs the system to trigger this skill on very broad, everyday phrases such as ‘地下探险’ or ‘我要写盗墓小说’, and even says it should ‘主动使用’. That increases the chance of unintended activation in loosely related conversations, causing the agent to override user intent, pull in this skill when not requested, or route sensitive user content into a complex multi-step workflow without clear consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is so broad that it can trigger on generic phrases like '地下探险' or '编个盗墓故事', causing the agent to invoke this skill in loosely related creative contexts without clear user intent. Over-broad routing can override more appropriate skills, increase prompt-surface exposure to this skill’s strong internal instructions, and lead to unintended file/task orchestration behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill hard-codes a specific author persona and stylistic/cultural framing ('你就是天下霸唱') without user opt-in, which can steer outputs into a fixed voice, language, and literary identity regardless of user preference. While not directly enabling code execution or data exfiltration, it can mis-handle user intent, create unwanted impersonation-style behavior, and reduce user control over generated content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The evaluation content reinforces a very broad trigger surface for the skill, including generic requests like '帮我想想' and ordinary writing-help phrasing that can match users who are simply asking for general creative assistance. This can cause the agent to invoke a highly specialized role unexpectedly, reducing user intent fidelity and enabling prompt-routing hijack behavior where normal writing tasks are steered into this skill without sufficient specificity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation description is overly broad and uses vague triggers like '当需要从那多视角讨论盗墓小说大纲时' without clear routing constraints. In a multi-skill agent, this can cause over-invocation or accidental selection in loosely related contexts, leading to inappropriate delegation, prompt-scope bleed, or reduced control over which specialized behavior is activated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description defines the skill entirely in Chinese and frames it as a specialized Chinese-language novelist persona, which effectively constrains language/locale. Because there is no explicit user choice or opt-in for language, this is a natural-language locale policy concern under the rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The output format and all surrounding instructions prescribe a single Chinese-language response structure, with no indication that the user may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file describes who may invoke the skill and under what general circumstance, but it does not define specific trigger phrases, exclusion conditions, or negative examples. Phrases like '由主编调用' and '当主编把全部正文交给你时' leave ambiguity about exactly how invocation is detected and when similar formatting requests should not activate the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs saving a TXT file to a 'specified output path' and creating the target directory if it does not exist, without any path restrictions, validation, or safety checks. In an agentic environment, this can enable arbitrary filesystem writes or directory creation if an upstream caller passes a sensitive or attacker-controlled path, potentially overwriting files or placing content in unintended locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file instructs the agent to act as a specific Chinese author persona ('你就是蔡骏,中国心理悬疑小说领军人物'), and the entire interaction format is fixed in Chinese. This can violate language/locale policy when the user has not opted into Chinese output or a Chinese-language persona.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.