Back to skill

Security audit

新建压缩(Zipped)文件夹

Security checks for vulnerabilities and agentic risk

Overview

This is a simple writing helper for Chinese short-video scripts and does not request code execution, data access, persistence, or privileged permissions.

Install this if you want a Chinese-language short-video script formatter. Be aware it may take over broad requests like “write a script” and will apply its default format, duration, and Chinese line-length rules unless you specify otherwise.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The descriptions require output rules tied to Chinese, such as "每句口播台词不超过15字" and the English description explicitly says each line must be within 15 Chinese characters. This imposes a language/locale-specific constraint by default rather than offering a user choice or documenting that the skill is only for Chinese-language scripts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match ordinary writing-related conversation, which can cause unintended skill activation. In an agent environment, overbroad activation can override normal assistant behavior, produce unwanted structured outputs, and increase the chance of prompt-routing mistakes when the user did not actually request this specialized skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

L026 says the skill should '无需额外提问,直接产出脚本' after receiving a request, but L034 says if the topic is missing it should '追问一次'. These instructions actively conflict about the intended behavior for incomplete input, creating an intent-level inconsistency in the skill's own documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.