Back to skill

Security audit

Character-Builder

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed character-skill generator made of Markdown references; it can create persistent skill files, so users should approve destinations before saving generated skills.

Install only if you want a Chinese-oriented character-skill generator. Before allowing it to save output, review the generated skill contents, choose the destination yourself, and require confirmation before overwriting or adding files under your skills directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description lists activation phrases such as "生成角色", "创建角色", "角色设计", and "character builder" without narrowing context or giving exclusion conditions. These phrases are generic enough to match ordinary creative requests, which could cause unintended invocation of this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asserts strong execution behavior around generating and assembling skill files, while also stating rigid modification rules, but it does not prominently require explicit user consent before writing to disk. In an agent environment, implicit filesystem writes can create persistent artifacts, overwrite existing content, or unexpectedly alter a skills workspace from a natural-language request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented shell redirection command creates or overwrites a merged prompt file without any safety guard, path validation, or user warning. In practice, users or agents may execute this verbatim, causing silent overwrites or unintended file creation, especially in shared or pre-populated skill directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The final delivery step explicitly instructs outputting a complete skill directory to a filesystem path, but it does not require an explicit user-facing warning about persistent changes or confirm whether the destination already exists. Because the skill is designed to activate from common language about creating characters, this increases the chance that a benign content-generation request results in unexpected persistent writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad generic terms such as '生成角色' and '创建角色', which can be invoked during ordinary conversation without clear user intent to activate this skill. In an agent system, broad triggers increase the chance of unintended activation, causing the agent to follow this skill's file-generation and workflow instructions in contexts where the user did not ask for it.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L0106 states every dimension must be filled and cannot be skipped, with missing values explicitly marked 未定义. This is reinforced by L0283 and L0907. Yet the functional-role example at L1224-L1231 says AI roles do not need full C1/C3/C4 filling, and L1246 explicitly marks body/culture/celebrity dimensions as 不适用 and skipped. That is an active contradiction in the documented intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L0115-L0116 says the assembled output consists of SKILL.md + character-data.md + character-requirements.md and is written to a standard skill directory. But later L0364-L0366 defines references/ as the output location for core data, and L0911-L0924/L0943-L0945 further change the expected structure by adding optional references/dialogue.md or references/exemplars/*.md. These are not just omitted details; they present conflicting descriptions of the intended output artifact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented merge/export command creates a combined prompt file from multiple local files but does not prominently warn about file creation or overwrite risk. Because this skill is framed as content, not code, hidden write semantics are more dangerous: a user or agent may treat it as harmless documentation while it materially alters the local filesystem.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

At L0191-L0192, the directory usage table says scripts/ and assets/ are absent (本技能无), implying no executable code/resources are part of the skill. However, L0175-L0183 provides a concrete cat ... > character-builder-prompt.md command and multiple later sections specify writing generated files to disk and standard skill directories, which is active operational behavior rather than a purely reference-only skill layout.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly directs output to '{skills目录}/{角色英文名}/' without a clear user-facing consent or warning that local filesystem state will be modified. In agent environments with write access, implicit persistence can overwrite files, create artifacts unexpectedly, or be abused as a stepping stone for cluttering or poisoning local skill directories.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The example strategy sets the AI tool's cultural default to “全球化+多语言(根据用户语言切换)”, which is acceptable, but elsewhere the generated role examples prescribe fixed Chinese-language interaction styles such as “正常中文交流”. This imposes a language default without clearly offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file appears to require Chinese comprehension for all task definitions, workflow descriptions, and examples. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill hard-codes a culturally specific default ('当代中国城市') for realistic characters when the user has not supplied that information. In a character-generation system, this can silently bias outputs, overwrite user intent, and produce inappropriate or exclusionary personas, especially when the generated skill is reused downstream as if the defaults were neutral facts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown exemplar is entirely framed in Chinese and presents the skill behavior/content in a single fixed language with no indication that users can opt into another language. Under the policy rule, forcing a specific language or locale without user choice is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill hard-codes Chinese as the response language (e.g., '正常中文交流') without indicating it should adapt to the user's language. This can override user preference and create prompt-scope conflicts, reducing usability and potentially causing unsafe misunderstandings if a user cannot accurately interpret important outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document requires real professions to be grounded in the Chinese occupational classification system (with ISCO as an alternative in some places), which embeds a region-specific standard into a supposedly general-purpose character builder. This can misclassify non-China contexts, constrain culturally accurate generation, and propagate jurisdiction-specific assumptions into downstream character skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The phrase "默认全球/英语+目标用户语言" imposes English as a default locale in natural-language guidance. Under the policy, forcing or defaulting to a specific language without clear user opt-in can be a language/locale policy issue, especially since nearby text does not frame English as optional user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L42 specifies that the character '能说流利的上海话和国语,偶尔蹦出几句英语', which imposes concrete language and locale behavior as part of the output. The file does not indicate that the user can choose or opt into these language constraints, so this is a natural-language locale-policy issue under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

Line L37 specifies that the character's mother tongue is Norman French and that Middle English is spoken but disdained ("会但不屑于用"). While this is historically framed, it still encodes a fixed language-use policy in natural language rather than presenting language choice as user-selectable or clearly bounded as historical context only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Line L080 states that scientific writing is conducted in English, which imposes a specific language expectation in the skill content. The file does not indicate that users may choose another language or that this is an optional, user-driven preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.