Back to skill

Security audit

Writing Inspiration

Security checks for vulnerabilities and agentic risk

Overview

This is a simple writing-prompt skill with no code execution, persistence, credentials, or hidden data access.

Installers should expect a Chinese-oriented writing inspiration helper. It may activate on broad writing requests and includes a small week/month journaling reference even though it says diary writing belongs elsewhere, but it does not request system access or perform actions outside conversation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match many ordinary writing requests, which can cause this skill to activate when a more appropriate skill or the base assistant should respond. In an agentic system, over-broad routing is a security and safety concern because it can steer users into the wrong workflow, suppress better-suited safeguards, or create policy bypass through skill misselection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill content is written to enforce Chinese-language interaction without offering user choice or documenting a locale constraint. This can create unsafe or unreliable behavior in multilingual environments by overriding user language preference, causing misunderstanding of prompts, consent issues, or incorrect routing/output when the surrounding system expects language preservation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

该 markdown 文件整体以中文标题、说明和示例对话呈现,并在示例中默认让助手以中文回应。根据规则,若技能在自然语言层面强制特定语言而没有提供用户选择或明确的地域/语言范围,属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill should be used for writing help excluding diary writing, directing diary use to a different skill. However, this file contains a dedicated '周记 / 月记扩展' section built on a diary framework, which semantically supports diary-like journaling behavior beyond the declared scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.