Back to skill

Security audit

首席创意官

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a creative-strategy prompt, but it asks for command execution and file write authority while also describing broad automation behavior that is not clearly scoped to creative work.

Review before installing. Use this only if you are comfortable granting a creative-writing skill broad local read/write and command execution capability; otherwise request a version limited to creative brief, brand narrative, and review outputs without exec and with clearer file boundaries.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a creative strategy and brand storytelling tool, yet it declares read/write/exec capabilities that materially expand it into a generic automation surface. This mismatch is dangerous because users or orchestrators may invoke it under a low-risk creative pretext while granting powerful filesystem and execution permissions unrelated to its stated purpose.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The documentation advertises broad automation behaviors such as file parsing, API handling, data aggregation, and command execution that are outside the stated creative-officer function. This creates capability ambiguity that can cause the agent to over-apply the skill in unrelated contexts and normalize high-risk operations under an innocuous label.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Arbitrary command execution is not justified for a creative strategy skill and substantially increases the attack surface. In this context, exec could be abused to run shell commands, access local data, modify the environment, or chain into further compromise, all while appearing to be a harmless creative-assistance tool.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is so broad—covering efficiency, automation, batch processing, and workflow optimization—that it could match many unrelated requests. Because the skill also exposes powerful tools, vague routing conditions increase the chance that an agent will select this skill in inappropriate contexts and hand it capabilities beyond what the user intended.

Static analysis

No suspicious patterns detected.