Back to skill

Security audit

fight-video-create-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a local fight-storyboarding reference library, but it contains prompt-generation templates and detailed combat instructions that conflict with its stated boundaries.

Review before installing. Use it only for fictional choreography/storyboard work, strip or clearly reclassify the prompt-generation templates, and do not use its move library as real-world fighting instruction. Be deliberate before allowing it to ingest private files, because confirmed ingestion persists material into the skill’s reference library.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (65)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
声明描述的是一个面向内容构思与资料入库维护的技能:接收用户战斗构想,结合场景、动作分镜、招式库、技能库和示例剧本进行检索与编译,并可吸收用户资料到 reference 库。实际代码却只是一个离线验证工具,检查 JSON 元数据和关联文件是否一致、字段是否完整、技能库格式是否符合约束。它没有处理用户输入、没有生成战斗剧情或动作方案、没有执行检索编排、也没有导入资料文件到资料库。虽然它涉及“路由元”与 reference 目录,和“维护路由元”在主题上略有相关,但其实际能力仅限于结构校验,和声明中的核心用途存在明显主功能不一致,因此应判定为描述与行为不匹配。

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The document explicitly states that it does not generate prompts and that prompt packaging or platform/model syntax must not enter the design. However, the later output section includes a dedicated '用户要“视频提示词”' mode and specifies a directly usable prompt structure, which materially expands the behavior beyond the stated limitation.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
Early guidance says the scheme must not generate any model or platform prompts, and that prompt packaging and related syntax are forbidden. Later sections explicitly define a workflow and output template for '视频提示词' and even a concise body '可直接复制到提示词中', directly contradicting the earlier prohibition.

Missing User Warnings

High
Confidence
97% confidence
Finding
This file is a detailed library of combat techniques, targeting points, takedowns, and finishing moves, presented as reusable building blocks without any safety framing, de-escalation guidance, or constraints limiting use to fictional choreography. In the context of a skill that transforms user fight concepts into scene plans and action chains, the content can directly facilitate realistic violent action design and lower the barrier to generating harmful assault guidance.

Missing User Warnings

High
Confidence
98% confidence
Finding
This file is a dense repository of step-by-step violent combat techniques, including strikes to the throat, eyes, knees, spine, chokes, joint breaks, and follow-up attack chains after takedowns. In the context of an agent skill intended to retrieve and compile action-design material, this substantially lowers the barrier to generating realistic instructions for harming people, and the absence of safety boundaries or filtering makes misuse straightforward.

Missing User Warnings

High
Confidence
97% confidence
Finding
This file is a structured move library for violent incapacitation, including control points, chained strikes, takedowns, and explicit 'termination conditions' aimed at disabling an opponent. In the context of a skill that retrieves and compiles combat material for users, the absence of a clear safety boundary, fictional-use restriction, or anti-harm disclaimer increases the risk that the content could be operationalized for real-world violence rather than purely narrative choreography.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file explicitly presents itself as a prompt-generation template, which conflicts with the skill's declared boundary that it does not generate prompts. This creates capability drift and can cause an orchestrating agent to perform higher-risk prompt-authoring behavior than operators expect, undermining policy controls and user trust.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The title and core capability statements actively instruct the agent to generate standard action prompts or storyboard prompts, directly contradicting the advertised scope. Because these are imperative behavior-setting instructions near the top of the file, they are likely to override operator expectations and induce unsafe or unauthorized outputs during runtime.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The task framing repeatedly states that the only final output should be a directly usable video-generation prompt, conflicting with the documented purpose that excludes prompt generation. In skill-based agent systems, this kind of hidden capability expansion is dangerous because routing, permissions, and safety review may rely on the declared scope rather than the actual embedded instructions.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file explicitly instructs the agent to produce a model-ready 15-second video prompt as its sole deliverable, which directly contradicts the skill metadata stating it is not responsible for prompt generation. This creates a specification mismatch that can cause downstream agents to perform higher-risk content transformation than operators expect, weakening safety boundaries and auditability.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The manifest states the skill is used for fight-plot ideation, action design, storyboard design, and reference ingestion, and explicitly says '不负责提示词生成'. However, this document defines the '唯一任务' as generating '一份可直接用于目标视频生成模型的完整动作提示词', which is direct prompt generation rather than merely upstream planning or material retrieval.

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill metadata and all operating instructions are written to require Chinese-language interaction, and there is no statement that the user may choose another language. This is a natural-language locale policy issue because the file imposes a specific language by default without opt-in or a documented regional/compliance reason.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The reference explicitly instructs the model to act as an AI video prompt expert and generate prompt-like action scripts, which conflicts with the declared skill boundary that it is not responsible for prompt generation. This kind of instruction drift is dangerous because hidden reference content can override or blur the intended scope of the skill, causing the agent to produce outputs outside approved functionality and weakening downstream policy enforcement.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The entire instruction set is written as a mandatory Chinese system-role prompt and does not indicate that the user may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The file explicitly frames blood extraction ('provide blood or equivalent life imprint') as a prerequisite and later depicts finger-biting and blood activation as part of the mechanism, but provides no safety warning, fictional-only framing, or prohibition against real-world imitation. In a creative action-design skill, that omission can normalize minor self-harm as a usable technique and may encourage unsafe copying by users seeking realism or roleplay guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The file defines the primary retrieval terms as only “单体、群体”, which are extremely generic labels rather than domain-specific activation phrases. Without narrower scope, exclusion conditions, or concrete examples, this skill could be selected for many unrelated requests that mention single-target or group scenarios.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The manifest-style metadata and routing descriptions are entirely written in Chinese, and the file does not indicate that this language requirement is optional, user-selected, or tied to a documented region-specific constraint. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a locale-policy issue.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The phrase “直接帮我创建” is overly broad and can be triggered by ordinary user language without clearly establishing that the user wants this specific fight-design workflow. In an agent setting, broad activation language increases the chance of unintended routing, causing the skill to take over requests and pull in specialized combat-creation logic when the user did not mean to invoke it.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
These lines prescribe mandatory writing rules using Chinese phrasing such as '必须' for how techniques must be described, but the skill file does not indicate that users may request another language or localized terminology set. Because the guidance is framed as hard requirements for output style, it can force a specific language/locale convention without opt-in.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The file is entirely written as a prescriptive skill specification in Chinese and provides no indication that users may opt into another language or locale. Under the policy rule, forcing a specific language without user choice can be a natural-language policy violation unless clearly justified as region-specific, which is not documented here.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This section includes guidance on restraining vulnerable body areas, including the neck, chest/abdomen, and joints, but frames it only as choreography constraints rather than explicit safety or fictional-use limitations. In a combat-design skill, such material can be repurposed into real-world restraint tactics, increasing misuse risk even if the stated purpose is action design.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
技能描述强调基于场景、动作分镜方案、招式库、技能库和示例剧本进行检索编译,以及资料入库维护;而本文件新增完整的视觉风格选择功能和20个默认场景选择功能,直接承担创意生成与风格化输出引导。尽管与视频内容相关,但这已超出“仅做剧情/动作设计且不做提示词生成”的已声明边界。

Vague Triggers

Medium
Confidence
91% confidence
Finding
This is a manifest-style file, so vague trigger review applies. The description says to use the skill when the user requests things like '专业分镜', '运镜设计', or '提供打斗分镜', which are broad creative requests and not tightly scoped to this specific high-impact combat template, increasing the chance of unintended invocation.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
Line L003 says this is a '可直接用于...视频生成模型的单文件提示词模板', and later sections repeatedly require delivery of full prompt output for a target model. This directly conflicts with the surrounding skill intent provided in the manifest, which says the skill does not generate prompts.

Static analysis

No suspicious patterns detected.