Back to skill

Security audit

迪士尼12法则动画视频制作(参考图)

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only animation storyboard helper with no hidden execution, credential access, network behavior, or persistence.

Safe to install from a security perspective. Before using it, only upload reference images you are comfortable sharing with the agent workflow, and avoid sensitive personal photos, IDs, private locations, confidential material, or copyrighted images you do not have rights to use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example invocations and workflow are written as if the skill operates in Chinese by default, including user prompts and AI responses in Chinese. This creates a language/locale constraint without any indication that users may choose another language or opt in to Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire skill instructions are written as a Chinese-only workflow, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience for a documented reason. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly asks users to upload reference images for characters, scenes, and objects, but it provides no warning against sharing personal, sensitive, or copyrighted imagery. This can lead users to disclose faces, homes, documents, location clues, or other identifying content that may be retained, processed, or reused beyond their expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese and provides no indication that language selection is optional or user-configurable. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

技能描述强调基于动画法则生成专业分镜脚本,但该输出在字幕中出现“坑 1:乱帮私活”,与当前“熬夜脸救星”主题及动画脚本创作目标无关,像是残留或串台内容。这表明实际产出未稳定遵循所宣称的脚本生成意图,存在描述与行为层面的不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The user-facing content fields throughout the JSON are entirely in Chinese, including theme, content, platform, style, and tone, with no indication that language selection is configurable or user-chosen. Under the policy rule for natural-language violations, this can be treated as forcing a specific language without opt-in unless the skill is explicitly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.