Back to skill

Security audit

Tech Article CN

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Chinese technical-writing assistant, but it requests broader file, shell, web, and agent powers than its writing workflow clearly needs.

Install only if you want a Chinese-focused technical article workflow and can run it with approval controls. Consider removing Bash and narrowing Agent delegation, file access, and triggers before routine use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:34
Finding

Overly Broad Tool Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34–44
Vulnerability Type: Excessive tool authorization
Risk Level: Medium

Vulnerable Configuration

yaml
allowed-tools:
  - Read
  - Write
  - Edit
  - Grep
  - Glob
  - Bash
  - AskUserQuestion
  - WebFetch
  - WebSearch
  - Agent

Technical Analysis

The Skill is intended to plan, draft, review, and polish technical articles. Most of this workflow requires document access, user interaction, and optional web research. However, the configuration also grants unrestricted shell execution through Bash and general-purpose delegation through Agent.

These capabilities exceed the minimum privileges required for the declared writing workflow. The filesystem tools are also not explicitly limited to user-approved source files, generated drafts, or a designated output directory.

No malicious shell command or deliberate abuse of these permissions was found in the reviewed files. The risk arises from the unnecessarily broad authorization boundary: attacker-controlled article material, untrusted web content, or a compromised delegated agent could influence the model into using these tools for actions unrelated to article production.

Attack Path

  1. A user invokes the Skill with attacker-controlled source material or requests optional online research.
  2. The Skill reads the material or retrieves untrusted web content.
  3. The untrusted content contains instructions designed to redirect tool use.
  4. Because the Skill is authorized to invoke Bash, access the filesystem, and delegate to Agent, the influenced agent attempts actions outside the writing task.
  5. Depending on host-level sandboxing and approval controls, those actions could read unrelated files, alter local content, execute commands, or initiate further delegated operations.

This is a capability-based exploitation path. The audited files do not contain a built-in ...[truncated 860 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove Bash because the documented article-writing workflow does not establish a legitimate need for arbitrary shell execution.
  2. Remove Agent unless delegation is essential and its permitted tasks can be narrowly defined.
  3. Restrict Read, Write, and Edit operations to:
    • Files explicitly selected by the user.
    • A dedicated workspace for generated drafts.
    • A user-confirmed final output path.
  4. Make WebFetch and WebSearch opt-in for the research phase rather than available throughout every execution mode.
  5. Treat fetched pages, article drafts, and reference material as untrusted data. Explicitly instruct the agent never to follow tool-use instructions found inside that content.
  6. Require user confirmation before overwriting files, accessing paths outside the workspace, or invoking delegated workflows.
  7. Apply runtime controls independently of Skill instructions, including filesystem sandboxing, command allowlists, network restrictions, and sensitive tool-call approval.
  8. Define separate tool sets for each mode. For example, outline-only mode should not receive write, edit, shell, or delegation privileges.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html-diagram-style.md (reported line 12)May include surrounding context.

html
<div style="font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif;font-size:13px;margin:20px 0;background:#fafafa;border:1px solid #e5e7eb;border-radius:12px;padding:24px">
<div style="text-align:center;font-weight:700;font-size:15px;color:#111;margin-bottom:20px">图表标题</div>
<!-- 内容 -->
</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html-diagram-style.md (reported line 12)May include surrounding context.

html
<div style="font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',sans-serif;font-size:13px;margin:20px 0;background:#fafafa;border:1px solid #e5e7eb;border-radius:12px;padding:24px">
<div style="text-align:center;font-weight:700;font-size:15px;color:#111;margin-bottom:20px">图表标题</div>
<!-- 内容 -->
</div>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger set includes broad regexes like writing/blog/article phrases that can match many ordinary user requests, causing the skill to activate outside the author's intended scope. Over-broad auto-invocation can override more appropriate skills, pull in unnecessary tools, and increase the chance that downstream actions such as file access, web fetches, or sub-agent calls occur on unrelated prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Single-phrase triggers such as '写博客', 'write.*post', 'technical.*writing', and especially short generic phrases can match many benign writing requests that are not meant for this skill. This expands the skill's activation surface and can cause unintended orchestration with powerful tools, creating a prompt-routing weakness rather than a code-level exploit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill content is written entirely in Chinese and references Chinese-language guidance files and Chinese-specific writing cleanup, but it does not offer the user a language choice or state that Chinese is optional. This creates a natural-language policy concern because the skill appears to assume a fixed language/locale for output and interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document title and instructions are entirely in Chinese and use mandatory language such as '必须遵循统一风格', which imposes a specific language/locale convention. The policy allows locale constraints only when users are given a choice or when the constraint is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains natural-language instructions that effectively force a specific language/locale for use of the skill content. Under the policy rule, language constraints should either be optional for the user or explicitly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is written as prescriptive guidance for technical writing in Chinese, including language-specific rules such as Chinese-English spacing and discouraging mixed-language phrasing. Under the policy rule, forcing a specific language or locale without user opt-in can be a natural-language policy violation, and the document does not present this as optional or region-specific.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
97% confidence
Finding

The trigger '写稿' is extremely short and generic, making accidental invocation likely across many unrelated writing tasks. In a skill with access to Read, Write, Edit, Bash, WebFetch, WebSearch, and Agent, unintended activation increases the risk of inappropriate file operations, web activity, or agent chaining on prompts that never intended to use this workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, starting from the title and continuing throughout the document. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction "避免纯中文标题" requires avoiding fully Chinese titles, which is a language/locale constraint stated as a blanket rule rather than an optional recommendation. This can conflict with organizational language-choice policies because it does not offer the user or author a language opt-in or alternative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document states that '中文技术文章:15-25 个字效果最好', which imposes a language-specific recommendation without indicating that users may choose another language or that the guidance is limited to a Chinese-language context. Under the policy, forced language or locale guidance without opt-in or explicit justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.