Back to skill

Security audit

toutiao-master

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Toutiao writing and local article-audit skill that discloses its local report files and shows no network, credential, account-login, or background behavior.

Use this skill for Chinese Toutiao article drafting and pre-publication review. When running the script, point it only at files or directories you intend to audit because it will read matching drafts and create local JSON report files there; its compliance output is guidance, not a guarantee that Toutiao will approve a post.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises script-driven file read/write behavior (python scripts/toutiao_audit.py, reports written to user directories) but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity where a host agent may grant broader filesystem access than users expect, increasing the risk of unintended file access or modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Broad trigger keywords can cause the skill to activate for generic content-writing requests outside the user's intent. In this skill, accidental activation matters because it can steer users toward local script-based auditing and file handling behavior, expanding the skill's effective reach beyond a narrowly scoped Toutiao workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Generic trigger terms like broad article-creation phrases are unreliable for safe routing because they overlap with many ordinary writing tasks. This can lead to inappropriate invocation of the skill's prescriptive workflow and associated script usage in contexts where the user did not request Toutiao-specific review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

Ambiguous keywords that are not clearly bound to the target platform can misroute unrelated requests into this skill. While the content is primarily advisory rather than overtly dangerous, misactivation still increases confusion and could prompt unnecessary file-based auditing actions or irrelevant policy guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is entirely framed in Chinese and presents the review standard as the required process, but it does not indicate that Chinese is optional or that users may choose another language/locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that the skill supports other languages or that Chinese is an explicit user-selected option. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and module docstring describe a skill for content production quality control and auditing, which implies analysis of article files. However, the implementation also creates JSON report files on disk (audit_report.json or .audit.json), adding a file-modification behavior beyond pure auditing/inspection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code writes JSON audit results to disk in both batch and single-file modes via write_text, which is a file-modifying operation. Although the script prints the saved path after writing, there is no prior confirmation prompt, upfront warning in the module docstring, or explanatory comment near the write operations disclosing that running the script will create report files alongside the target path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all checklist content are written entirely in Chinese, presenting the checklist as a required publication gate rather than an optional locale-specific variant. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the locale restriction is clearly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template appears to require use in Chinese by presenting all instructions, examples, and labels exclusively in Chinese. Under the policy rule for language or locale constraints, a skill should not force a specific language unless it offers user choice or clearly states a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.