Back to skill

Security audit

storyforge-writing

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed StoryForge writing/workflow skill that reads project story materials and produces structured creative artifacts, with no hidden install hooks, credentials, or persistence found.

Install this only for StoryForge-style creative writing projects where reading local story markdown and knowledge files is expected. Review C-post workflows before using provider or DaVinci MCP tools, since those can create or modify media outputs, and keep imports/manual adoption under user control as the skill instructs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a creative writing framework, but it also instructs the agent to inspect repository structure, validate baselines, audit contract files, and run consistency checks over local assets. That mismatch can cause the agent to read more local files than a user would expect from a writing skill, increasing the risk of unintended data exposure or overbroad workspace access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file's natural-language content is entirely in Chinese, including operational notes and validation instructions, with no indication that the skill is region-specific or that users may choose another language. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The primary skill description is written as a directive in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is described entirely as a Chinese-language framework for a specific agent environment, and its operational instructions are written as mandatory behavior without offering the user a language or locale choice. Because no opt-in or alternate-language path is provided, this creates a natural-language locale constraint that may violate language-choice policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The loading criteria include broad phrases like requests for structured writing, StoryForge-style writing, or any task touching world/story/character/outline layers, which can cause the skill to activate for many loosely related prompts. Overbroad auto-loading increases the chance that unrelated user content is routed through this skill's file-reading and governance workflow, expanding access and influence beyond user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and all operational instructions are written exclusively in Chinese, and the contract does not indicate that language selection is optional or limited to a China-specific workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely presented in Chinese, including operational instructions and safety-relevant guidance, with no indication that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all user-facing natural-language content in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.