Back to skill

Security audit

jl-content-rewriter

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly designed to rewrite articles to avoid similarity checks and can read and write local files, so users should review it carefully before installing.

Install only if you intentionally want a Chinese article-rewriting workflow and you have rights to the source material. Avoid using it to republish third-party content without attribution, review any generated output for copyright and platform-policy compliance, and approve exact input/output paths before allowing file writes. Treat the referenced helper skills as additional dependencies that should be independently reviewed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
references/ai-humanizer.md:8
Finding

Dynamic Loading of Unpinned External Skills

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:61
Finding

Unrestricted File Input and Predictable Adjacent Output Writes

Content
View full analysis
Remediation
View remediation

other

Note
Location
references/user-command.md:42
Finding

Platform-Specific Plagiarism Detection Evasion Workflow

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly includes originality checks, similarity scoring, platform-specific plagiarism risk thresholds, and iterative optimization to lower detectable similarity while preserving the source meaning. That goes beyond ordinary editing and materially enables evasion of plagiarism detection and reposting controls on publishing platforms.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger terms are very broad and include generic requests like '改写' and '二次创作', making accidental or unintended activation likely. Because the skill performs file reads/writes and promotes plagiarism-evasion workflows, overbroad triggering increases the chance of unsafe invocation in unrelated contexts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Claiming to 'remove AI flavor' and convert AI text into human text is an evasion-oriented capability that can help conceal machine generation from reviewers, readers, or policy systems. In this context it is paired with low-similarity rewriting, which increases the likelihood of deceptive use rather than simple style improvement.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed workflow systematically preserves the original information while changing wording, structure, and sequence, then measures similarity and iterates to reduce platform-detectable duplication. In context, this is a concrete operational playbook for laundering source content into derivative copies designed to evade moderation and plagiarism checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs saving output files into the source directory and describes file creation behavior without a prominent warning or explicit confirmation step. Any skill that modifies filesystem state should clearly disclose where files will be written and require user approval to avoid unintended data sprawl, overwrites, or privacy issues.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states the final deliverable should contain only the processed article content with no intermediate process or metadata. However, the later required response template instructs the AI to output processing information, statistics, previews, and workflow details, which contradicts the earlier 'only article content' requirement at the intent/documentation level.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file describes granting the AI permission to read and reply to WeChat messages, which is a privacy-impacting behavior. Although the text briefly says it 'won't touch other things,' it presents the permission casually and does not include a clear warning about message access, data handling, or the need to avoid exposing sensitive chats.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation criteria rely on vague judgments such as '进入到第7步' and '仍感觉AI味任然不是"无菌"', without defining the workflow, the evaluation standard, or when the skill should not be used. This can cause inconsistent or unintended invocation because different users or agents may interpret these conditions differently.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
93% confidence
Finding

The document discloses an internal absolute filesystem path to another local skill ('~/.openclaw/workspace/skills/ai-humanizer/SKILL.md'), which exposes environment structure and enumerates available capabilities. In an adversarial setting, this can help an attacker map the agent's local workspace and craft follow-on prompts or dependency-targeting attacks against known skill locations.

Content

Scanner excerpt · references/ai-humanizer.md (reported line 10)May include surrounding context.

调用方式:

text
读取:~/.openclaw/workspace/skills/ai-humanizer/SKILL.md
应用:核心原则(AI生成的文本更具人性化。重写文本使其听起来自然、具体且有人情味)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The conditions for calling 'humanizer-zh' say it should run after 'ai-humanizer' if AI traces still need removal or for creative writing when text still feels '无菌', but these are subjective and not operationally defined. The file does not specify measurable criteria, explicit scope limits, or negative examples, so invocation may overlap broadly with normal rewriting tasks.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
93% confidence
Finding

This line similarly reveals an internal skill path ('~/.openclaw/workspace/skills/humanizer-zh/SKILL.md'), enabling capability and environment enumeration. While not an exploit by itself, the skill context makes it more sensitive because it tells an attacker exactly which auxiliary skill exists and where it is expected to reside.

Content

Scanner excerpt · references/ai-humanizer.md (reported line 22)May include surrounding context.

调用方式:

text
读取:~/.openclaw/workspace/skills/humanizer-zh/SKILL.md
应用:核心原则(去除文本中的 AI 生成痕迹,审阅 AI 生成内容、优化写作风格、让文字不那么像机器生成的)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents all instructions and labels exclusively in Chinese, which can constitute a language/locale policy violation when no user opt-in or justification is provided. The content does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains natural-language instructions entirely in Chinese and begins with a mandatory requirement phrased as '必须满足', which indicates a fixed language/locale expectation. Under the policy, forcing a specific language without user opt-in or clear regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger language is broad and workflow-coupled rather than tied to explicit user intent, which can cause the polishing skills to run automatically in situations the user did not request. In this context, unintended invocation can propagate hidden transformations to user content and cascade into additional skill loading without clear consent or narrowing conditions.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/writing-polish.md (reported line 10)May include surrounding context.

调用方式:

text
读取:~/.openclaw/workspace/skills/blog-rewriter/SKILL.md
应用:核心原则(对文章进行润色、排版)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/writing-polish.md (reported line 20)May include surrounding context.

调用方式:

text
读取:~/.openclaw/workspace/skills/chinese-writing-polish/SKILL.md
应用:核心原则(去除文本中的 AI 生成痕迹,审阅 AI 生成内容、优化写作风格、让文字不那么像机器生成的)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction explicitly directs the system to remove signs of AI-generated writing as a default behavior, without indicating that this should occur only when the user asks for it. That creates a policy and trust risk because it encourages concealment-oriented rewriting and may materially alter provenance, style, or disclosure expectations for generated content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The instruction says the rewritten output must use a natural, everyday colloquial tone, which imposes a particular linguistic style by default. Under the policy, forced language or locale/style constraints should either be optional or clearly offered as a user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

The file's natural-language instructions and guidance are entirely in Chinese, which may amount to an implicit language constraint for users who do not read that language. There is no indication that the language choice is optional or that the skill is intended only for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The article says the AI will automatically fetch, parse, and organize content from supplied links, which implies network access and transfer of user-supplied data to external resources or services. The description does not warn readers that using this feature may involve outbound requests and associated privacy or data-governance considerations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This plain-text skill content presents all instructions and descriptions in a single language with no indication that users may choose another language or that the locale restriction is intentional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to 'generate the final file and save it' and provide a save path, but it does not define safe write boundaries, destination constraints, overwrite behavior, or require explicit user confirmation before writing. In an agentic environment, ambiguous save behavior can lead to unintended file creation or overwriting in sensitive locations, even if the author likely intended normal document export.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions require outputs to be '符合日常生活化的语气' and to avoid complex wording in favor of '通俗易懂的日常表达'. This imposes a specific language/register choice by default rather than offering the user a style or locale preference, which matches the policy concern for forced language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.