Back to skill

Security audit

阿德影视制作大师

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent film-production helper, but it should be reviewed because it forces its own watermark onto every exported PDF and can activate from broad trigger terms.

Install only if you are comfortable with a Chinese-language, realistic live-action workflow and with generated PDFs being locally saved and automatically watermarked with the skill’s branding. Review PDF output before sharing it with clients or publishing it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:176
Finding

Mandatory Promotional Watermark Hijacks PDF Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 176
Vulnerability Type: Forced output modification and promotional branding
Risk Level: Medium

Complete Vulnerable Instruction

The complete instruction at the affected line, translated into English, is:

text
All PDF exports must use headless Chrome to ensure standardized formatting. Every export must include the semi-transparent watermark "Ade Film Production Master" at an angle of approximately 30 degrees, centered, light gray, approximately 8% opacity, covering the entire page without obscuring the body text, and displayed on every page.

Technical Analysis

The Skill unconditionally directs the agent to place its own promotional watermark on every page of every exported PDF. This requirement is embedded in the Skill instructions rather than presented as an optional, user-controlled export setting.

When the Skill is loaded, this instruction changes the expected output from a clean user-requested document into a branded document. The behavior therefore constitutes instruction-level output hijacking: the Skill author controls part of the final deliverable for promotional purposes, regardless of whether the branding is relevant to or requested by the user.

The instruction does not provide an unbranded export path and does not require informed user consent before applying the watermark. Although the manifest declares PDF generation and headless Chrome access, it does not clearly disclose that every generated page will contain mandatory third-party branding.

Attack Path

  1. A user installs or invokes the Skill for screenplay or storyboard production.
  2. The user requests that the generated content be exported as a PDF.
  3. The Skill follows the embedded instruction and invokes the declared headless Chrome PDF-generation workflow.
  4. Before delivering the PDF, the workflow adds the Skill author's watermark across every page.
  5. The user receives a persistently branded docum ...[truncated 887 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional watermark requirement from the Skill instructions.
  2. Make watermarking an explicit, default-disabled export option.
  3. Obtain clear user consent before adding any watermark or promotional attribution.
  4. Provide a clean PDF export path that does not contain Skill-author branding.
  5. If watermarking is selected, allow the user to configure its text, placement, opacity, and affected pages.
  6. Disclose optional watermark behavior in README.md, manifest.yaml, and the PDF export confirmation prompt.
  7. Keep PDF generation focused on formatting the user-requested content and prevent unrelated promotional material from being inserted automatically.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states the skill will auto-trigger for broad, common requests such as converting stories into scripts or mentioning common AI video tools. Overly broad activation can cause the skill to engage without clear user intent, potentially hijacking unrelated conversations and steering outputs into its rigid workflow or exposing user-provided content to unintended processing stages.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is broad enough to trigger on generic discussion of films, stories, or common AI media tools, which can cause the skill to activate outside the user's actual intent. Over-broad routing increases the chance of inappropriate capability injection, unexpected file/output operations, or misleading workflow steering in unrelated conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructions are written to position the agent as a Chinese-language persona and specify output style without giving the user a language or locale choice. This creates a language/locale constraint that is not presented as optional or region-specific, which can violate language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
69% confidence
Finding

All visible natural-language metadata, including the skill name, description, triggers, inputs, and outputs, are presented only in Chinese, with no indication that users may choose another language. This can amount to a language/locale policy issue if the skill is expected to support broader users unless the Chinese-only scope is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes broad terms such as '影视制作', '剧本改编', and names of common creative tools, which can cause the skill to activate in many loosely related conversations. Over-broad activation increases the chance of unsolicited file-writing/PDF-generation workflows being invoked when the user did not explicitly request this skill, raising the risk of inappropriate handling of user content or unexpected side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely framed in Chinese, beginning with a Chinese-titled example section and describing the examples as the style/structure reference to follow. That creates a natural-language locale constraint without any indication that users may choose another language or opt in to Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The README states '严格真人写实 / 照片级超写实,严禁卡通、动漫、插画,' which forces a single stylistic mode. This is a natural-language constraint that restricts output format without documenting user opt-in or clarifying that this is an intentional, fixed-scope skill limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs PDF export and current-result saving without clearly warning that files may be created or persisted. This can violate user expectations around local file creation and retention, especially when working with unpublished scripts, proprietary drafts, or sensitive source material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction to read an external reference file encourages workspace content access without warning or consent boundaries. Even if the referenced file is benign, normalizing silent reads from the workspace can expose unrelated local content patterns and weaken least-privilege behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.