Back to skill

Security audit

Cangjie Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate book-to-skill generator, but it should be reviewed because it turns untrusted book text into future agent instructions without explicit prompt-injection safeguards.

Install only if you are comfortable with a skill that creates persistent skill files from book content. Use trusted or reviewed source texts, inspect generated SKILL.md files before loading or sharing them, and avoid feeding adversarial documents or books that contain prompt-like instructions until the workflow adds explicit untrusted-content handling.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:71
Finding

Untrusted Book Content Can Influence Generated Agent Instructions

Content
View full analysis
/candidates/.md`. ``` From `SKILL.md:121-129`: ```markdown For each verified unit, populate `templates/SKILL.md.template`: - R (Reading): original quotation, no more than 150 characters per passage - I (Interpretation): rewrite the methodological structure in your own words - A1 (Past Application): an example used by the author - A2 (Future Trigger): situations in which the user would need this; write this into the Skill's `description` field - E (Execution): executable steps numbered 1-2-3 - B (Boundary): situations where the method does not apply ``` From `methodology/02-stage1-parallel-extract.md:13-20`: ```markdown Each sub-agent receives: - `BOOK_OVERVIEW.md`, providing global context - The book text, or a path to the text - The corresponding extractor prompt Spawn all five sub-agents simultaneously through the Agent tool. ``` From `methodology/02-stage1-parallel-extract.md:30-43`: ```yaml id: f01 title: Inversion Thinking type: framework source_chapter: Chapter 3 source_quote: | "Think in reverse, always think in reverse..." summary: | ... tags: [decision, mental-model] ``` From `methodology/04-s ...[truncated 4029 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The primary descriptive content begins in Chinese and presents the skill in that language by default. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the file clearly offers language choice or documents a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill metadata and content strongly bias operation and output toward Chinese without offering the user a language choice. This can cause unexpected behavior, reduce usability for non-Chinese users, and increase the chance that users approve file-writing or analysis results they cannot easily review, but it is not an exploit-enabling issue by itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create a substantial directory tree and multiple files in the workspace, but the user-facing overview does not clearly warn that filesystem writes will occur. In an agent environment, undisclosed writes can surprise users, clutter or overwrite workspace content, and create audit/privacy issues if source text or derived notes are persisted without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s operative instructions are written entirely in Chinese, which imposes a specific language/locale on skill behavior without any opt-in or alternative. Under the stated policy, forcing a language without user choice is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L03 states the instruction entirely in Chinese and directly addresses the agent as operating within the pipeline in that language, with no indication that the user or system can opt into another language. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction text is written as a direct requirement in Chinese, indicating the skill operates in a specific language by default. There is no visible option for user language choice or explanation that this extractor is intentionally limited to a Chinese-language pipeline for compliance or region-specific reasons.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's operative instructions are written directly in Chinese and address the agent as performing its role in that language, with no indication that language choice is optional. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s operational instructions are written directly in Chinese and define the assistant’s role and behavior in that language, with no indication that users can choose another language or that the locale restriction is required for a region-specific workflow. This creates a natural-language locale policy concern because it implicitly enforces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written as an instruction set in Chinese and provides no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational guidance exclusively in Chinese and does not offer any language choice, fallback, or note that the skill is intended only for Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs that if the source book is in English, the skill must provide the English original plus 'your own Chinese translation'. This imposes a specific output language requirement rather than offering a language choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains all user-facing instructions in Chinese and does not provide an opt-in, alternative language, or justification for the locale restriction. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown instruction file uses Chinese throughout and does not provide an opt-in, alternative language, or justification that the skill is intended only for Chinese-speaking users. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and throughout-text instructions require producing human-facing notes and talking points in Chinese, including colloquial style requirements such as '大白话' and '像朋友聊天'. Because the file gives no user opt-in, fallback, or justification for a Chinese-only locale constraint, this is a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest says this skill is for distilling a book into callable skills, notes, and phrase libraries, and explicitly narrows its trigger/purpose. The README adds author biography, multiple social platform links, and an externally hosted image QR code, which are not justified by the skill's functional purpose and introduce promotional/external-reference content outside the declared context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This file is presented as the Japanese version of the README, but line L125 switches to the heading "More Skills" in English rather than maintaining the selected locale or explicitly offering a language choice. That creates a minor language-policy inconsistency because the document imposes an unexpected language change without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is natural-language documentation, and its content uniformly forces a specific language/locale for readers. Under the stated policy, language constraints should either offer user choice or be explicitly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.