Back to skill

Security audit

中文公文写作技能

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a Chinese official-document generator, but its recommended font setup can permanently change system font and Windows registry settings without an in-script confirmation.

Review this skill before installing. Use the document generator only with safe output paths, and do not run the font installer with administrator privileges unless you have checked the font files and are comfortable making persistent OS font and registry changes. Prefer manual per-user font installation or project-local font handling where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The stated purpose is official document generation, but the skill also describes OS font installation, copying files into user/system font directories, refreshing font caches, and even registry-related behavior per the finding. This mismatch is dangerous because users or orchestration systems may grant the skill broader trust than warranted, enabling host modification under the guise of document creation.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/dialog_manager.py (reported line 119)May include surrounding context.

python
DialogStep.CONFIRM: self._prompt_confirm(),
        }
        
        return prompts.get(self.current_step, {"type": "text", "message": "未知步骤"})
    
    def process_user_input(self, user_input: str) -> bool:
        """处理用户输入,返回是否继续对话"""

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/smart_prompts.py (reported line 249)May include surrounding context.

python
DialogStep.CONFIRM: self._prompt_confirm(),
        }
        
        return prompts.get(self.current_step, {"type": "text", "message": "未知步骤"})
    
    def process_user_input(self, user_input: str) -> bool:
        """处理用户输入,返回是否继续对话"""

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

The script executes an external command via os.system("fc-cache -fv"), which introduces unnecessary shell invocation and host-side command execution. Although the argument is constant and not directly user-controlled, this still expands the skill's behavior beyond document generation and can be abused or fail unpredictably in restricted environments.

Content

Scanner excerpt · scripts/install_fonts.py (reported line 163)May include surrounding context.

python
shutil.copy2(font_file, dest)
                
                # 更新字体缓存
                os.system("fc-cache -fv")
            
            return True

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 applies to all file types and covers language/locale policy violations in natural-language content. The README presents the skill entirely in Chinese and frames its interaction examples and usage around Chinese-language official-document generation, without explicitly stating that the language requirement is inherent to the task or offering user choice/opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to run a font installation script and copy font files into system font directories, which can modify the host environment and may require elevated privileges. Even though this is documentation rather than executable code, it encourages system-level changes without clearly warning about privilege requirements, trust boundaries, rollback steps, or the risks of installing bundled font files.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation instructs use of Python scripts and shell commands that can write files and modify the host environment, yet it declares no explicit tool restrictions. In an agent setting, undeclared shell and file-write capability increases the chance of over-privileged execution and unintended side effects, especially when the skill also includes system-level installation steps.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger condition is extremely broad, stating that any request related to reports, notices, formal files, or document creation should invoke this skill. Overbroad activation can cause the wrong skill to run on ordinary conversations, increasing the chance that file-writing or shell-capable behavior is invoked unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L003与全文描述默认该技能生成的是中文党政机关公文,且未说明这是面向特定语言环境的专用技能,也未提供语言或地区选择。按规则,强制特定语言而无用户选择或清晰、受限的地域适用说明,构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a user font directory and copying files into it. In context, a document-generation skill should not silently establish durable filesystem state, because that can outlive the task and be abused or simply surprise users and administrators.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

  1. 创建字体目录:

    bash
    mkdir -p ~/.fonts
    
  2. 复制字体文件:

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a user font directory and copying files into it. In context, a document-generation skill should not silently establish durable filesystem state, because that can outlive the task and be abused or simply surprise users and administrators.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

  1. 创建字体目录:

    bash
    mkdir -p ~/.fonts
    
  2. 复制字体文件:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description states the skill is a government document generator in Chinese, and the implementation throughout the file hardcodes Chinese document labels, headings, and output text. Because the skill does not offer any language or locale selection, it imposes a specific language by default, which matches the policy-violation category for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

标题“党政机关公文生成技能 - 使用示例”以及全文示例均以中文表述,呈现出技能默认面向单一语言环境。按 SQP-3,若技能强制特定语言而未提供用户选择、未说明区域限定或合规理由,应视为自然语言政策风险。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · fonts/README.md (reported line 56)May include surrounding context.

bash
# 复制字体到用户字体目录
mkdir -p ~/.fonts
cp *.ttf ~/.fonts/

# 更新字体缓存

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
60% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/GBT_9704-2012_党政机关公文格式.md (reported line 321)May include surrounding context.

md
# 11    式样

A4 型公文用纸页边及版心尺寸见图 1;公文首页版式见图 2;联合行文公文首页版式 1 见图 3;联合行文公文首页版式 2 见图 4;公文末页版式 1 见图 5;公文末页版式 2 见图 6;联合行文公文末页版式 1 见图 7;联合行文公文末页版式 2 见图 8;附件说明页版式见图 9;带附件公文末页版式见图 10;信函格式首页版式见图 11;命令(令)格式首页版式见图 12。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The dialog manager stores raw user input and full dialog history, including potentially sensitive official-document content, timestamps, secrecy classification, and organizational details, without any visible consent, minimization, masking, retention control, or access-control logic in this component. In the context of government-style document generation, this increases confidentiality risk because users may enter regulated or sensitive material that is then persistently retained in memory/log structures and potentially exposed to downstream systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to natural-language policy issues in any file type, including docstrings, comments, literals, and sample content. This script hardcodes Chinese-language instructions, labels, and output phrasing throughout, which can violate a language/locale policy when no user choice or explicit region-scoped justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script's docstrings and user-facing console messages are entirely in Chinese, which imposes a language choice on users without opt-in. While the tool is related to a Chinese document standard, the file does not explicitly document that the locale/language restriction is intentional or region-specific for user interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code writes into system font locations and, on Windows, modifies the registry to register fonts. For a document-generation skill, changing host system configuration is a privileged side effect that exceeds expected scope and could affect the entire machine or require elevated rights.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installation path performs host system writes and Windows registry modification without an interactive confirmation, dry-run, or prominent disclosure. Silent system modification is dangerous because users invoking a document tool may not expect persistent OS-level changes or the need for elevated privileges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script enumerates host font directories and copies installed font files into the skill's local folder, accessing and duplicating host assets unrelated to the immediate document-generation request. This expands data access scope and may copy proprietary or licensed fonts without user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code embeds all user-facing descriptions, prompts, hints, and sample content in Chinese only. That imposes a fixed language on users without any visible opt-in or documented locale restriction, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The save method writes a DOCX directly to the caller-supplied filepath with no validation, overwrite protection, or disclosure. In an agent setting, if an attacker can influence output_path, this can overwrite existing files or write to unintended locations on the host filesystem, causing integrity issues and possible data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

这是一个 markdown 文件,因此需按 SQP-2 的 markdown 规则检查是否对可能影响用户数据或系统状态的行为进行了告知。L038 的示例会生成并写出 output_notice.docx,但页面未提醒该操作会在本地文件系统创建或可能覆盖同名文件。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

L065 调用 generate_document 生成 output_request.docx,属于会影响本地文件数据的行为。当前示例说明仅展示调用方式,没有向用户披露会产生文件写入结果或潜在覆盖风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.