Back to skill

Security audit

公文写作

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese official-document drafting and checking assistant, with expected local document review features and some trigger/install caveats.

Install only if you want Chinese official-document drafting and checking. Avoid providing classified, confidential, or sensitive internal materials unless they are properly desensitized, and prefer explicit invocation of the skill because some triggers are broad. If installing manually, prefer a trusted marketplace flow or a pinned package/version where available.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The skill advertises authoring assistance but also specifies QA and scoring workflows over existing .docx/.md/.txt files, with structured reporting and script execution patterns. Hidden auditing capabilities are risky because they encourage users to provide internal documents under a narrower trust assumption than the actual behavior warrants.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill advertises authoring assistance but also specifies QA and scoring workflows over existing .docx/.md/.txt files, with structured reporting and script execution patterns. Hidden auditing capabilities are risky because they encourage users to provide internal documents under a narrower trust assumption than the actual behavior warrants.

Ae1

High
Category
analysis-evasion
Content
+ 7 种行政公文 + 11 种专题模板 + 信函式文件 + 应急预案/会议议程/慰问信/专项总结/联合行文)、公文专用措辞规范及安全保密要求;成稿后可用 `scripts/quality_score.py` 做五维 100 分质量评分(合规/完整/规范/准确/文风),用 `scripts/format_check.
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
+ 7 种行政公文 + 11 种专题模板 + 信函式文件 + 应急预案/会议议程/慰问信/专项总结/联合行文)、公文专用措辞规范及安全保密要求;成稿后可用 `scripts/quality_score.py` 做五维 100 分质量评分(合规/完整/规范/准确/文风),用 `scripts/format_check.
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
+ 7 种行政公文 + 11 种专题模板 + 信函式文件 + 应急预案/会议议程/慰问信/专项总结/联合行文)、公文专用措辞规范及安全保密要求;成稿后可用 `scripts/quality_score.py` 做五维 100 分质量评分(合规/完整/规范/准确/文风),用 `scripts/format_check.
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
+ 7 种行政公文 + 11 种专题模板 + 信函式文件 + 应急预案/会议议程/慰问信/专项总结/联合行文)、公文专用措辞规范及安全保密要求;成稿后可用 `scripts/quality_score.py` 做五维 100 分质量评分(合规/完整/规范/准确/文风),用 `scripts/format_check.
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation examples and trigger phrasing are broad enough to match common user requests like writing reports, summaries, or meeting minutes. Overly broad trigger boundaries can cause unintended auto-invocation, leading the skill to process sensitive workplace content or override a user's intended workflow without clear consent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The capability boundary states “仅支持中文公文写作” and excludes English documents, which is a language restriction presented as a fixed policy in natural language. The README does not offer user language choice or explain a documented locale/compliance justification for enforcing this constraint as a policy matter.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The FAQ explicitly says the skill auto-triggers on generic requests like asking for an annual summary or official-format document. In a workplace/government-document context, that increases the chance of accidental activation on sensitive or regulated material, making unintended data exposure or policy bypass more likely.

Lp3

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding
The skill instructs the agent to read local reference files and user-supplied materials, but it does not declare an explicit tool scope such as allowed-tools or permissions. That creates an authorization ambiguity where a runtime may grant broader file access than the user expects, increasing the chance of unintended local file reads during document drafting or validation flows.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Several triggers are broad everyday phrases such as 写报告, 工作总结, and 正式报告, which can activate the skill in conversations that do not intend government-style drafting. Unintended activation is more dangerous here because the skill may then read references, request sensitive organizational details, or shift the conversation into compliance-oriented handling without clear user intent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The file states that if a user needs an English version, the skill should respond that it only supports Chinese official documents. This is a language/locale restriction expressed in natural language, and the file does not present it as a user-selectable option or opt-in choice.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
This markdown file presents all instructions and examples exclusively in Chinese and is specifically framed around Chinese official-document writing. The file does not indicate that the language constraint is optional or that the skill is limited to a justified region-specific audience, so it may violate the language/locale policy.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
Line L047 explicitly marks "英文公文" as unsupported and states that any English request or English source material is out of scope. This is a natural-language policy concern because the file enforces a language restriction without offering user choice or documenting a justified locale-specific constraint.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The entire guide is written as a mandatory Chinese-language official-document polishing standard for “公文” and prescribes fixed wording conventions, but it does not state that this locale/language constraint is optional, user-selected, or limited to a justified region-specific use case. Under the policy, forcing a specific language/locale without opt-in can be a natural-language policy violation.

Vague Triggers

Medium
Confidence
94% confidence
Finding
L012 says the skill should execute when the user explicitly asks to “润色”, “优化语言”, or “再读一遍”. In particular, “再读一遍” is a common conversational phrase and the file does not provide exclusions or contextual limits, so it could cause unintended invocation outside this specific polishing workflow.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The file is a markdown document, so SQP-3 applies. Throughout the document it defines a quality standard specifically for Chinese official-document writing, including mandated terminology, formatting, and phrasing, but it does not state that this language/locale constraint is optional or limited to users who explicitly want Chinese-language government-document evaluation.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The title and the entire template set are written exclusively in Chinese and framed as standard templates for report generation, with no indication that users may request another language. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern unless the restriction is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The title states this is a specialized vocabulary and phrasing guide for 国央企 official documents, and the document consistently prescribes a single Chinese political-bureaucratic register as mandatory. Under the policy, forcing a specific language or locale without user choice or an explicit justified regional constraint is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file-level description and all user-facing CLI help/output are written only in Chinese and the scoring logic is explicitly for Chinese government-report writing, with no option for users to select another language or locale. This is a natural-language locale constraint embedded in the skill that lacks an explicit user choice or opt-in mechanism.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
72% confidence
Finding
The trigger '述职' is short and context-light, so it may match routine discussion or requests outside the intended official-document workflow. In this skill, accidental activation can still expose users to unnecessary probing for internal work details or local-document processing paths.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
75% confidence
Finding
The single-character trigger '函' is highly ambiguous and prone to accidental matches in normal Chinese text. Because the skill can pivot into official-correspondence generation and related file-reading workflows, such broad activation creates avoidable confusion and unnecessary data handling.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
73% confidence
Finding
The trigger '请示' is too generic and can occur in ordinary administrative conversations without intending to invoke this specific skill. Accidental invocation is undesirable because the skill is designed for formal official-document workflows and may solicit sensitive organizational context.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
73% confidence
Finding
The trigger '批复' is brief and can match general discussion of approvals or responses. Even low-severity accidental activation matters here because the skill targets formal state/enterprise documents and includes auxiliary validation behaviors beyond simple text completion.

Static analysis

No suspicious patterns detected.