Back to skill

Security audit

cultivation-novel-architect

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese creative-writing skill for cultivation novels and does not request risky access, persistence, code execution, or hidden data handling.

Install this if you want Chinese-language cultivation-novel writing help. Be aware it may activate on broad genre terms, so users discussing the genre analytically may need to clarify when they do not want creative generation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list consists of very broad genre terms such as 修真、修仙、仙侠 and related common vocabulary, which can cause the skill to activate in many loosely related conversations. Overbroad activation increases the chance of unintended prompt injection surface or inappropriate takeover of user requests, even though the skill itself is content-generation focused rather than system-modifying.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list consists of very broad genre terms like 修真、修仙、仙侠、功法 and related nouns, with no clear activation boundaries, exclusions, or requirement to confirm user intent first. This can cause the skill to activate in loosely related conversations and steer outputs unexpectedly, increasing prompt-injection surface and causing inappropriate skill invocation, though the domain here is creative writing rather than a high-risk operational task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description and the entire instruction set are written as a Chinese-only skill, and the examples and trigger terms assume Chinese-language interaction. There is no indication that users may opt into another language or locale, which can be a language-policy issue when the skill is otherwise general-purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.