Back to skill

Security audit

拾光册视频海报与记忆手帐

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed poster/journal workflow with privacy-bounded optimization and review steps, not hidden collection or unsafe execution.

Before installing, be comfortable with an agent processing supplied videos, frames, references, and journal metadata for creative output. Use the optimization branch only with aggregate, privacy-safe packs, and keep raw prompts, media, links, identifiers, IPs, and credentials out of telemetry inputs. Review generated posters before publishing because the skill is designed to audit and block questionable outputs rather than guarantee they are ready to ship.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The workflow explicitly allows use of feedback and real exposure/click/share/save measurements and the skill metadata says it may use user data to optimize results. That broad optimization language can enable collection or secondary use of behavioral data beyond what is necessary to generate or audit a poster, creating privacy and purpose-limitation risk if implemented without explicit consent, minimization, and retention limits.

Context-Inappropriate Capability

High
Confidence
82% confidence
Finding
The release-gate section mandates adversarial and counterfactual tests, which is defensible for robustness, but in this skill context the metadata also includes '对抗审稿' (anti-review/evasion). That combination increases the risk that the workflow could be repurposed to systematically evade platform review, provenance checks, or moderation by optimizing outputs against review conditions rather than just improving quality.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description includes a broad natural-language trigger around 'using user data to optimize functionality,' which can cause the agent to activate the skill in contexts unrelated to the core poster/journal task. Overbroad triggers increase the chance of unintended collection, reuse, or processing of user content based only on vague wording rather than explicit consent and bounded scope.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Using 'same-meaning request' language creates an unbounded semantic trigger that lets the skill treat many loosely related user prompts as authorization to enter the optimization branch. In a skill that mentions user-data optimization, that ambiguity is dangerous because it can expand processing beyond the user's clear, informed intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation rule is broad enough to activate the workflow for ordinary feature-improvement requests, which can cause the agent to enter a telemetry- or usage-analysis path without clear user intent or explicit gating. In this skill, that matters because the workflow is tied to "利用用户数据优化功能效果" and optimization packs derived from usage data, so over-triggering could expand access to sensitive operational data or cause privacy-sensitive processing in contexts where the user only wanted generic product advice.

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill explicitly introduces a path to use user data for optimization in plain language, which creates a meaningful risk of repurposing user-provided content beyond the immediate task. Even though the text includes some privacy limits later, the trigger is broad enough that users may not realize their content could enter an optimization workflow, leading to secondary use of sensitive media, prompts, or metadata.

Ssd 3

Medium
Confidence
95% confidence
Finding
A dedicated branch activated by user intent to 'optimize using user data' normalizes data reuse as part of routine operation and relies on natural-language interpretation instead of strict authorization controls. In a multimedia skill that may handle videos, frames, text, and provenance, this can expose highly sensitive personal content to retention, analysis, or cross-task reuse beyond the original purpose.

Static analysis

No suspicious patterns detected.