Back to skill

Security audit

翰林学士

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed academic polishing tool that sends user-provided text to DeepSeek for rewriting, with no hidden persistence or unrelated local access found.

Install only if you are comfortable sending the text you submit to DeepSeek. Avoid using it for confidential, unpublished, regulated, or third-party-restricted manuscripts unless that external processing is permitted by your policies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · main.py (reported line 82)May include surrounding context.

python
),
        },
    }
    return prompts.get(mode, prompts["polish"]).get(language, prompts["polish"]["zh"])


def polish_text(text: str, mode: str = "polish", language: str = "auto") -> dict:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes external capabilities (environment access and network use via DeepSeek API) but does not declare any explicit tool scope or permissions boundaries. This creates an authorization and transparency gap: the runtime may permit broader capability use than users or reviewers expect, making misuse of secrets or outbound requests harder to audit and constrain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly says user text will be sent to the DeepSeek API, but it provides no warning, consent step, or data-handling notice before transmitting potentially sensitive manuscript content to a third party. Academic drafts often contain unpublished research, personal data, or confidential material, so silent external transfer can cause privacy, confidentiality, and compliance issues.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · main.py (reported line 11)May include surrounding context.

python
# DeepSeek API 配置
DEEPSEEK_API_URL = "https://api.deepseek.com/v1/chat/completions"
SKILL_ID = 7665153655141580854

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This request transmits user text and system instructions to an external service over the network. In the context of academic polishing, the text may contain confidential manuscripts, personal data, embargoed results, or proprietary research, making third-party transmission security-relevant even if TLS is used.

Content

Scanner excerpt · main.py (reported line 123)May include surrounding context.

python
}

    try:
        response = requests.post(
            DEEPSEEK_API_URL, headers=headers, json=payload, timeout=60
        )
        if response.status_code >= 400:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill sends the full user-supplied paper text to DeepSeek's external API, which can expose unpublished research, sensitive academic material, or regulated data to a third party. There is no in-code notice, consent flow, masking, or policy guardrail indicating that user content leaves the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction requires Chinese replies for Chinese input and English replies for English input, imposing a language policy automatically. The file does not indicate that users may opt into a different reply language or override this behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The code automatically selects either Chinese or English prompts and output behavior based on character heuristics when language is set to "auto". This imposes a language choice without explicit user opt-in at runtime, which can conflict with language/locale policy expectations requiring user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.