Back to skill

Security audit

武侠小说创作主编

Security checks for vulnerabilities and agentic risk

Overview

This skill automates Chinese wuxia novel writing and local story-file handling, with no evidence of exfiltration, persistence, destructive code, or credential access.

Install only if you want an autonomous Chinese wuxia novel workflow. Use a dedicated project/output directory, because the skill may inspect existing outline or manuscript files there and may create multiple generated text files without asking for confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation examples are broad enough to match generic requests like writing a story or novel, which can cause the skill to trigger when the user did not specifically intend to invoke a fully automated multi-step novel-generation workflow. In context, this is risky because the skill claims it will proceed autonomously, potentially scanning existing files and producing many outputs without explicit user awareness or confirmation.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrases are extremely broad and include generic requests like '写个故事', '来个故事', and '想写小说', which can cause the skill to auto-activate for many unrelated writing tasks. In a multi-skill agent, this increases the chance of unintended invocation of a skill that performs file scanning, file reads, and file writes, expanding data access beyond user expectation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The entire skill is presented as Chinese-only, with all invocation examples, workflow, and outputs assuming Chinese-language use, but there is no statement offering alternative language support or an explicit opt-in to a Chinese locale. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes automatic breakpoint detection, scanning existing files, and generating multiple output artifacts, but does not clearly warn users up front that their files may be inspected and that the skill may create many files automatically. This can lead to unexpected access to user content and unanticipated file creation, which is a safety and transparency issue even if no malicious behavior is intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description and operating persona are fixed in Chinese and assume a Chinese-language wuxia-writing workflow, but there is no opt-in or user choice for language/locale. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless the constraint is explicitly justified and documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs automatic path selection, directory listing, reading existing files, and saving intermediate/final files, but does not present this as a clear user-facing consent boundary. That creates a privacy and least-astonishment issue: a user asking for story help may not realize the skill will inspect local directories and ingest prior content from disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This plain-text file consists entirely of Chinese narrative content and provides no option for alternate language or locale. Under the language/locale policy rule, forcing a single language without user opt-in or documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The eval prompt is broad enough to match ordinary creative-writing requests, which can cause this skill to trigger in situations where a more general writing assistant should respond. That increases the chance of unintended routing, overreach, and user confusion, especially because the skill description explicitly says to proactively activate on many common phrases.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This prompt similarly lacks boundaries and may collide with common requests like 'help me write a novel' or 'write a story,' leading to accidental invocation outside the intended domain. Because the expected behavior says not to ask clarifying questions and to proceed automatically, misrouting is more dangerous: the skill may take over decisions without verifying user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The continuation prompt is ambiguous because many users say 'continue my novel' without meaning this specific wuxia workflow. In this skill, auto-detecting prior outline/volumes and continuing from them without tighter scope checks can misapply specialized behavior to unrelated writing tasks, causing inappropriate file/context handling and incorrect agent routing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description fixes the skill to Chinese wuxia prose style and presents that as the required output mode, rather than offering language or locale selection. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and core instructions are entirely in Chinese and define the skill's behavior specifically for reviewing wuxia novels, but they do not offer any user language/locale choice or explicitly justify a mandatory Chinese-only policy. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to write a TXT file to a user- or caller-specified path and to create directories if they do not exist, but it provides no path validation, sandboxing, or requirement for user confirmation before modifying the filesystem. In an agent setting, this can enable unintended writes to arbitrary locations, overwriting files, or creating attacker-chosen directories if the upstream caller or prompt is influenced by untrusted input.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Lines L016-L019 state that the skill should tell the user only one thing: '小说写完了,请查收', implying no intermediate user-facing messages. But L073-L083 explicitly instruct the skill to tell the user what existing files were detected and where writing will resume before starting work. This is an active contradiction in the skill's own instructions about intended behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions require use of Chinese full-width punctuation and Chinese quote marks, imposing a specific locale/style policy by default. There is no indication that the user can opt into a different language or formatting convention.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.