Back to skill

Security audit

paper-writer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed academic paper-writing workflow with local validation scripts, but users should treat the “submission-ready” framing carefully under academic-integrity rules.

Before installing, confirm this fits your academic-integrity policy: the skill can produce complete papers, so users should use it only where AI drafting is allowed or disclosed. Also be aware that citation verification may require lookup tools or a verifier context, and if that is unavailable the skill falls back to labelled self-checking rather than true independent verification.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for an authoring skill that writes a new academic paper from a prompt or specification. The supplied code does not generate text or compose papers at all. Its primary purpose is the opposite phase of the workflow: auditing an existing document’s citation apparatus for structural integrity. It reads a markdown file, locates the references section, extracts in-text citations and reference entries, checks for orphan citations/references, validates DOI/URL/ISBN syntax, and enforces some style-specific formatting constraints. That is materially different from the declared purpose and falls into proofreading/verification behavior that the description explicitly says this skill is not for. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose says the skill writes a new academic paper from requirements or a topic. The actual code does not author text at all; it only checks whether an existing markdown/plain-text document falls within specified length bounds under defined counting conventions. While length checking could be a supporting component inside a larger paper-writing system, the supplied code chunk itself has a materially different primary purpose: validation of document length. It also specifically processes an existing file and excludes references/sections, which aligns more with compliance checking than paper generation. No suspicious extra permissions or external resource access are present, but the core capability differs substantially from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is content creation: writing a new academic paper from a brief or topic. The supplied code does not perform any writing, drafting, citation handling, or paper generation. Instead, it parses markdown headings from an existing file and checks compliance with required section names and optional ordering, returning pass/fail via exit codes. This is a materially different primary purpose—document structure validation rather than paper authoring—so the description does not accurately represent the code's behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose is end-user paper writing from a prompt/topic. The supplied code instead operates as a deterministic citation extraction and verification gate for an already-written paper file. Its primary purpose is citation checklist emission and ledger consistency verification, which is much closer to citation checking/fact-verification workflow than paper drafting. There is no functionality for generating prose, organizing sections, meeting word counts, or composing a new essay/thesis chapter/literature review. The code’s inputs, outputs, and control flow all center on reading an existing markdown paper and a ledger JSON, extracting references, and blocking/pass decisions about citation resolution status.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly markets the skill as producing a complete, submission-ready paper for coursework-like use, yet it does not prominently warn that using AI-generated papers for real academic submission may violate institutional rules or constitute misconduct. In this context, the omission materially increases misuse risk because the skill is optimized for polished deliverables, citation handling, and compliance with assignment constraints, making deceptive submission easier.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This README presents the Chinese version as the active/default content with an English link, but within this file the instructions and behavior are effectively fixed to Simplified Chinese. That can be a language/locale policy issue when users are not explicitly offered a choice in the skill behavior itself.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises invocation examples using very broad, everyday phrasing such as generic requests to 'help me write a paper' or 'write an academic paper about X'. In hosts that route skills by fuzzy matching, this can cause the skill to activate unintentionally for adjacent writing tasks, increasing the chance of misrouting users into a workflow that produces full papers when they may have intended lighter assistance.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description says to use the skill for phrases like "write me a paper on…" and "turn a brief into a paper," but it does not define tighter trigger boundaries or exclusion examples beyond a few sibling tasks. This leaves activation scope somewhat broad for general writing requests and could cause unintended invocation when a user wants drafting help but not a full submission-ready paper.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states "language (EN or ZH only in v1; refuse others with a scope message)," which imposes a language constraint rather than offering the user a choice among supported locales. Under the policy, forcing a specific language or limited locale set without opt-in or clear justified regional scope is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
- REVIEW items → name each and its verdict, e.g. `REVIEW 2: hooks_2000 RESOLVED; katrina_2005
  NOT_A_CITATION (fresh verifier)`.
- Fallback A → `citations 17/17 self-verified, no independent verifier`.
- No verification completed → `citations 17/17 form-checked only, existence NOT verified`, and
  the paper is not presented as finished.
Also report any instruction you quoted from the brief or pool. Never write a bare "verified".

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The scope section states "EN + ZH only," reinforcing a hard locale restriction at the skill level. This is a natural-language policy issue because the skill mandates a limited language set instead of offering a user-selected language option or documenting a region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file prominently labels this variant as 'English' with an alternate Simplified Chinese link, which indicates language-specific documentation. Because the natural-language policy rule covers forced language or locale without opt-in, this is a mild policy concern unless the skill explicitly offers language selection in-use or documents a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file instructs use of specific fallback markers in English and Chinese: [SOURCE NEEDED] and [需要来源]. Under the language/locale policy rule, prescribing fixed languages without opt-in can be a minor policy violation when no user choice or regional justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown contains the phrase "选题" in an otherwise English document, which implicitly imposes a specific language/locale artifact without user opt-in or explanation. Under the policy rule, fixed language usage can be a natural-language policy issue when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L53 specifies that academic register is judged in the requested "EN/ZH," which implies an explicit language restriction to English or Chinese. The file does not state that users may choose other languages or that this locale limitation is justified as region-specific, so it may violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.