Back to skill

Security audit

Chat Distill

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently analyzes user-provided chat exports and can mimic a speaker’s style, but users should only use it with appropriate consent.

Install only if you are comfortable giving the agent access to the specific chat export you choose. Use it for chats you are authorized to analyze, avoid sensitive or third-party private content where possible, and do not use generated replies to impersonate someone deceptively.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk is a preprocessing utility for chat exports, not a style-distillation or reply-generation system. It detects file format, parses message records, filters system/media messages in some cases, optionally filters by speaker, and emits normalized JSON. While this could support a larger pipeline for style analysis, the declared purpose claims direct capabilities to analyze chat style and generate replies in someone's voice, which are absent from this code. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to read user-provided chat export files, but it does not declare any tool scope or permission boundary for that file access. In an agent environment, undeclared file-read capability increases the chance of overbroad or unintended access to local data, especially because the skill processes sensitive personal conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to analyze exported private chats and generate replies that mimic a real person's style, yet the description lacks a strong consent, privacy, and impersonation warning. That omission makes misuse more likely for non-consensual profiling, disclosure of sensitive conversational data, or deceptive impersonation in phishing/social-engineering scenarios.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill uses broad trigger language such as analyzing chat records or mimicking a speaker's tone, which can match many ordinary conversation requests and cause the skill to activate in contexts the user did not clearly intend. Because the skill handles sensitive personal communications and impersonation-style output, over-triggering raises privacy and social-engineering risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document labels the WeChat plain-text pattern as "Pattern (Chinese locale)", which indicates a locale-specific assumption in the skill instructions. Under the policy, language or locale constraints should either be optional for the user or clearly justified as region-specific; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file instructs the report to adapt to the chat language, but the embedded markdown template immediately fixes the title to Chinese ("# 聊天风格分析报告"). This can force Chinese output structure even when the user interaction is in another language, which conflicts with the stated language-choice behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown content presents core analysis dimensions primarily in Chinese while also using English labels and examples, effectively imposing a mixed language/locale format on users. The file does not state that the skill is Chinese-language specific, nor does it offer an opt-in or alternative language, which may conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.