Back to skill

Security audit

漫剧全流程串联引擎

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only creative workflow skill that may be verbose or over-triggered, but it does not show hidden, destructive, or data-stealing behavior.

Install this if you want a fully automated creative planning workflow and have the five companion skills available. Be aware that it can produce a long end-to-end package from a single request, and broad trigger wording may make it activate more often than expected.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad everyday phrases such as '开始创作' and '全流程', which can cause the skill to activate unintentionally outside the narrow manga-workflow context. Unintended activation is risky here because the skill is designed to auto-run a long multi-stage workflow and emit detailed downstream instructions without an explicit confirmation step.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly mandates automatic progression through all stages in one conversation and forbids asking the user for the next step, but it does not provide an upfront warning that later stages involve external tools and potentially costly or privacy-relevant actions. This increases the chance that users receive or follow extensive generation/execution instructions they did not intend to request in full.

Static analysis

No suspicious patterns detected.