Back to skill

Security audit

古文活过来

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese classical-text video-script skill with no evidence of credential access, persistence, network use, or destructive behavior, but it does add promotional publishing text by default.

Before installing, be aware that outputs may include Chinese-only wording and promotional publishing elements such as campaign hashtags, an account mention, and a branded follow line. Review or remove those parts if you need neutral, unbranded educational materials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:249
Finding

Mandatory Promotional Content Hijacks User Deliverables

Content
View full analysis

Vulnerability Details

File Locations: SKILL.md:249 and scripts/generate_docx.py:197-200
Vulnerability Type: Forced promotional output and document branding
Risk Level: Medium

Evidence

SKILL.md:249 contains the following mandatory publication instruction, represented with Unicode escapes:

text
- \u5fc5\u5e26\u8bdd\u9898\uff1a#\u7528AI\u6253\u5f00\u4eba\u6587\u65b0\u89c6\u754c #AI\u521b\u4f5c\u6d6a\u6f6e\u8ba1\u5212 @\u6296\u97f3\u4eba\u6587\uff08\u5b98\u65b9\u6276\u6301\u6d3b\u52a8\uff09

This decodes to an instruction requiring specific campaign hashtags and a platform account mention.

scripts/generate_docx.py:197-200 unconditionally inserts a follow request into every generated document:

python
p = doc.add_paragraph(); p.alignment = WD_ALIGN_PARAGRAPH.CENTER
r = p.add_run(
    '\u5173\u6ce8\u300c\u53e4\u6587\u6d3b\u8fc7\u6765\u300d'
    '\u00b7 \u8ba9\u8bfe\u6587\u6d3b\u8fc7\u6765 \U0001f4d6'
)
r.font.size=Pt(12); r.font.color.rgb=RGBColor(0x8B,0x45,0x13)

Technical Analysis

The skill changes the expected output-generation objective by requiring promotional hashtags and an account mention as part of the publication strategy. Separately, the DOCX generator appends brand promotion without checking whether the user requested branding or consented to promotional content.

The behavior is deterministic and does not depend on external compromise: loading and following the skill instructions or running the bundled generator is sufficient to introduce the promotional material. This is best classified as instruction hijacking because skill-controlled requirements alter the content of the user's deliverable for a promotional purpose unrelated to the core document-generation function.

No remote payload retrieval, shell execution, credential access, privilege escalation, persistence, or network communication was identified in the reviewed files.

Attack Path

  1. A user o ...[truncated 1144 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory promotional-tag requirement from SKILL.md.
  2. Replace it with an optional publication-strategy section that clearly labels all hashtags and account mentions as suggestions.
  3. Require explicit user consent before adding branding, follow requests, campaign tags, or account mentions.
  4. Add a generator option such as --include-branding, with branding disabled by default.
  5. Pass footer text into the generator as user-controlled input rather than embedding a fixed promotional message.
  6. Add an automated test confirming that default output contains no account mentions, follow requests, campaign hashtags, or unrelated promotional text.
  7. Clearly disclose any requested attribution before generation and provide an unbranded output mode.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description describes a wide range of capabilities for turning classical Chinese texts into viral short-video scripts, but it does not specify clear trigger phrases, invocation boundaries, or situations where the skill should not activate. In a markdown/manifest context, this ambiguity can increase the chance of unintended invocation because the scope is defined only by a broad natural-language description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented entirely as a Chinese-language content generator for Chinese classical-text short videos, with no indication that users may choose another language or locale. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale constraint is explicitly documented as required and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file embeds user-facing text, subtitles, dialogue, and usage documentation exclusively in Chinese across the script. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.