Back to skill

Security audit

写作AI味消除与禁忌扫雷仪

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local writing-editing skill with disclosed rule files and no evidence of hidden execution, exfiltration, or unsafe automatic system changes.

Safe to install for local writing review, but treat it as an editing aid rather than legal or policy approval. Before using private rules, add a .gitignore entry for rules/ or store those files outside the repository, because the package does not itself enforce the documented Git exclusion.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:82
Finding

Private Rule Files Are Not Protected from Accidental Git Disclosure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:82-84
Related Locations: references/custom-rules-template.yaml:2-3, README.md:56,140, README_CN.md:56,140
Vulnerability Type: Missing version-control exclusion for locally stored private rules
Risk Level: Medium

Vulnerable Code and Configuration

SKILL.md:82-84:

text
Private rules are used to hold company, team, and personal preferences. If a Skill with the same name exists in the workspace, use the workspace <SKILL_HOME> first; otherwise use the currently loaded Skill directory. The default directory is <SKILL_HOME>/rules/, with files company.yaml, team.yaml, and personal.yaml. The "list rules" operation must echo the actual rule file paths read. Missing files are skipped. The rule format and examples are in references/custom-rules-template.yaml. Private rules must not downgrade high_sensitive warnings in the public mapping library; attempts to do so must be rejected. Private rules must not be committed, packaged, or copied into public examples.

Rule management is entered only when the user explicitly invokes an add, list, modify, disable, or delete rule command. Before writing, display the proposed change and wait for confirmation.

references/custom-rules-template.yaml:2-3:

yaml
# Save locations: <SKILL_HOME>/rules/company.yaml, team.yaml, personal.yaml
# <SKILL_HOME> is the directory containing this Skill. These files are private user data and must be excluded from Git, archives, and external deliverables.

README.md:56,140:

text
Company, team, and personal preferences live under a local rules/ directory ignored by Git. Public releases never bundle organizational or personal rules.
text
Private rules remain local, are ignored by Git, and are excluded from public releases.

No .gitignore file exists in the audited project, so the documented Git exclusion is not implemente ...[truncated 2471 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a committed .gitignore file at the project root:

    gitignore
    rules/
    
  2. If the repository needs to preserve the directory structure, use a safe placeholder:

    gitignore
    rules/*
    !rules/.gitkeep
    

    Commit only an empty rules/.gitkeep file.

  3. Add a pre-publication or CI check that fails if private rule files are tracked:

    bash
    if git ls-files 'rules/*.yaml' | grep -q .; then
      echo "Private rule files must not be tracked."
      exit 1
    fi
    
  4. Before writing a rule, verify that the destination is under the intended <SKILL_HOME>/rules/ directory and that the repository's effective ignore configuration covers the file.

  5. Prefer storing private rules in a user-specific configuration directory outside the Git working tree. If this design is adopted, document the platform-specific location and migrate existing files safely.

  6. Retain the existing explicit confirmation and content-validation controls, but clarify that they supplement rather than replace filesystem and version-control isolation.

  7. Update README privacy claims only after testing that git check-ignore rules/company.yaml confirms effective exclusion.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says the skill triggers when users 'ask to polish, humanize, or rewrite' text, which are broad, everyday editing requests that could match many unrelated writing tasks. The description does not provide exclusion conditions or negative examples to clarify when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 109)May include surrounding context.

git clone https://github.com/muippt/mu-humanizer-minesweeping.git ~/.claude/skills/mu-humanizer-minesweeping

text

> Using a different agent? Put the directory wherever that tool loads Skills from. Project-level use works too: `.claude/skills/mu-humanizer-minesweeping`.

**2. Verify** — restart or reload your agent and confirm that the Skill is picked up

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes broad everyday phrases such as “润色一下”, “扫雷”, and “用词检查”, and the description says any natural-language writing task should invoke minesweeping even if the user did not explicitly request it. This can cause unintended activation on benign writing tasks, leading to unexpected policy overlays, unnecessary content transformation, or disclosure of internal rule judgments the user did not ask for.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that the written-taboo rule set currently covers only Chinese trigger expressions, while still applying the workflow broadly to natural-language writing. Without an explicit language choice or clear opt-in boundary, users may incorrectly assume equivalent review coverage across languages, creating a false sense of safety and inconsistent moderation behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document is explicitly scoped to English-only editing ('English AI Patterns' and 'Use for English writing quality editing') without indicating that users can choose another language or opt in to this locale restriction. That is a natural-language locale policy concern under the rule for language/locale violations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include very common requests such as “润色” and broadly state that nearly any natural-language writing, rewriting, or polishing task should activate the skill. In an agent environment, this can cause unintended invocation on ordinary user prompts, expanding the skill’s reach beyond explicit user intent and potentially applying rewriting or policy logic where it was not requested.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire file is written in Chinese and defines the skill's operational thresholds and preservation rules exclusively in that language, with no indication that users may opt into another language or locale. This can amount to a language-policy violation when a skill implicitly requires a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and opening description define the file as a Chinese-language pattern library and all examples/instructions are exclusively in Chinese. For a generally reusable skill artifact, this can amount to a language/locale constraint without any stated user choice or justification that it is intended only for Chinese-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README states 'Chinese and English editing; Chinese written-risk mapping,' which indicates a locale-specific limitation for one core capability. This is presented as a fixed constraint rather than an explicit user choice or clearly justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The README states "中英文编辑;中文书面风险映射", which means the skill's risk-mapping capability is limited to Chinese while the skill otherwise accepts Chinese and English input. Because this is presented as a fixed language constraint rather than a user-selectable option, it may violate language/locale policy expectations for user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This HTML file is a code file, so SQP-2 applies to user-facing behaviors that may affect privacy or system interactions. The GitHub and external hub links open remote destinations in new tabs, but the page does not disclose that these actions will connect to third-party services or download content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s title and all instructional content are written in Chinese and the scope statement says it applies to Chinese public communication and general written expression. This imposes a specific language/locale context without any indication of user choice or opt-in, which matches the policy category for language or locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.