Back to skill

Security audit

介绍文案大师(跨境/小红书/公众号等)

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Chinese copywriting guidance skill with no code execution, data access, persistence, or hidden behavior.

Install this skill if you want Chinese-oriented marketing copy, social posts, ads, landing pages, or sales text. For neutral writing or non-Chinese output, explicitly state the desired language, tone, and whether persuasive framing should be avoided.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
---

## Output Rules
Always optimize for clarity first, persuasion second, cleverness third.

Prefer:
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill is explicitly positioned as a Chinese copywriting specialist and repeatedly defaults to Chinese-platform tone and output behavior, without clearly stating that language should follow the user's request. In multilingual environments, this can override user intent, degrade output safety or usability, and cause incorrect language/locale handling for tasks that should remain neutral or in another language.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is extremely broad and can be invoked for many generic writing, editing, persuasion, and conversion-related requests. This creates prompt-routing risk: the agent may select this skill in contexts the user did not clearly intend, causing inappropriate specialization, persuasive framing, or scope overreach in unrelated tasks.

Static analysis

No suspicious patterns detected.