Back to skill

Security audit

xhs-stable-comic

Security checks for vulnerabilities and agentic risk

Overview

This is a content-generation skill for a Chinese Xiaohongshu AI-and-fitness account, with no executable code, installation hooks, persistence, or hidden data access.

Install this if you want Chinese Xiaohongshu content strategy and comic prompt help for an AI+fitness account. Review any generated fitness or nutrition content yourself, avoid sharing sensitive health data or personal photos unless needed, and do not treat the outputs as medical, nutritionist, or certified coaching advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger condition is broad enough that the file may be invoked for generic image-generation or illustration requests, not just narrowly scoped four-panel comic tasks. In a skill-routing system, this can cause unintended prompt injection of opinionated workflow rules, override more appropriate skills, or produce outputs misaligned with user intent, which becomes a security and reliability issue when skills are selected automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document title and operating instructions are written entirely in Chinese and instruct the agent to use this file when certain tasks are involved. There is no indication that users may choose another language or locale, so the skill embeds a fixed language assumption rather than offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction '优先后期加中文' effectively biases outputs toward Chinese without an explicit user-language check or opt-in. This can override user preferences, reduce usability for non-Chinese speakers, and create prompt rigidity, though it is not a direct security exploit. In this content-generation skill, the issue is less dangerous than in a safety-critical workflow, but it still represents unsafe instruction precedence over user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger examples are broad enough that the reference file may activate in loosely related requests, causing the agent to apply persona/visual bootstrapping when the user intended a narrower task. Over-broad activation increases the chance of instruction leakage, irrelevant steering, or unintended override of higher-priority task context. In this skill, the harm is mainly scope confusion and degraded reliability rather than direct compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction "默认用中文输出" forces a specific language/locale as the default behavior. Under the policy, language constraints should be user-selected or clearly offered as a choice unless narrowly justified as region-specific; this file does not explicitly provide a user language choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The guidance says to use this file when the user wants to "长期做同一账号的 4格漫画" and to prioritize another file first if the user lacks a persona/visual system, but it does not clearly define the boundary cases. This leaves uncertainty about when this asset pack should be selected versus other related resources.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The suggested triggers include generic request-style phrases such as “给我固定主角设定卡” and “给我固定画风设定卡” without additional scope constraints or exclusion conditions. In a markdown skill reference, this can make it unclear when the skill should activate versus when a user is just casually asking for brainstorming help.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is entirely written as Chinese-language operating guidance and does not indicate that users may choose another language or locale. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guidance says dialogue boxes or subtitle bars should be left blank or contain only short English placeholders. This imposes a language preference in the workflow without user opt-in, which is a natural-language locale policy concern under the language-choice rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.