Back to skill

Security audit

漫剧总控导演

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed creative workflow and quality-control skill with no executable code, credential use, persistence, or hidden data handling.

Install this if you want an agent style guide for managing and reviewing vertical comic production outputs. Be aware that generic phrases like quality review may activate it more often than intended, but the artifacts show only text-based workflow guidance.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad phrases such as ‘审核质量’, ‘导演Agent’, and ‘总控调度’, which can plausibly appear in ordinary user requests and cause unintended activation. In this skill’s context, accidental invocation is risky because the skill acts as a high-level controller that validates outputs and dispatches tasks to downstream workflow stages, so misrouting can affect multiple later steps rather than a single isolated response.

Static analysis

No suspicious patterns detected.