Back to skill

Security audit

公众号文章排版

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese self-media article formatter with disclosed local HTML templates and no evidence of hidden privilege, exfiltration, or persistence.

Install only if you want Chinese WeChat/Toutiao article-formatting templates. Review generated HTML before publishing, especially if formatting non-Chinese content or pasting user-supplied HTML, because the templates are optimized for zh-CN publishing workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-system.md (reported line 271)May include surrounding context.

7. 行内强调

html
<!-- 主色加粗文字 -->
<span style="color:PRIMARY;font-weight:600">强调文字</span>

<!-- 主色底高亮标签 -->

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", which hard-codes a specific language/locale for the skill's output. Under the policy, locale restrictions should either be optional for the user or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The HTML shell template hard-codes lang="zh-CN", which imposes a specific language/locale in the generated output. The file broadly serves as a design system template rather than a clearly region-limited compliance tool, and it does not offer any user choice or explain why Chinese locale must be enforced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This template sets lang="zh-CN" unconditionally, which enforces a specific locale in generated pages. Because the file presents reusable templates and does not provide a language-selection mechanism, this is a natural-language policy issue under locale choice requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document sets lang="zh-CN", which explicitly fixes the content locale to Simplified Chinese. Under the stated policy, forcing a specific language or locale without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document sets lang="zh-CN", which hard-codes a specific language/locale. Under the stated policy, locale constraints should either be optional for the user or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.