Back to skill

Security audit

短剧资产拆解

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese-language creative workflow for extracting short-drama visual asset notes, with only offline validation scripts and no hidden networking, persistence, or privileged behavior.

Install this only if your project uses the described Chinese short-drama asset workflow and you are comfortable with it updating visual-setting documents in your project. Review generated asset decisions before downstream prompt, storyboard, voice, or production steps consume them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose describes a content-processing skill for turning screenplay text into visual asset planning output across multiple asset classes (characters, scenes/locations, props, continuity). The actual code does none of that. It contains only validation logic for two structured data files: character records and look records. It verifies JSONL format, field presence, ID conventions, reference declarations, acceptance metadata, and that look.character_ref points to an existing character. There is no script ingestion, no extraction of visual details, no handling of locations or props, and no generation of readable design docs. This is a material purpose mismatch, not merely an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a content-analysis skill that reads scripts and produces human-readable visual asset setup information. The actual code chunk does not implement that behavior. It is a standalone self-test harness for an existing validator, exercising record validation against fixture data. While this may support a broader asset-processing system, the chunk itself neither parses scripts nor generates the described asset-setting output. Its primary purpose is materially different: test/QA for data validation logic.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says the skill is used when the user says phrases like “拆角色/场景/道具”, “做资产设定”, and “更新造型/道具状态”, which are fairly broad task descriptions rather than a narrowly defined invocation contract. It does not provide negative examples or clear limits distinguishing when these phrases should invoke this skill versus adjacent writing, storyboard, or prompt-generation skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L2 specifies "language":"zh-CN" in voice_direction, which imposes a concrete locale choice in natural-language configuration. The file does not indicate user choice, opt-in, or a documented region-specific justification, so this matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

Across the JSONL records, artifact and destination paths use Chinese-only naming such as "剧集", "创作者决策", and "设定集", with no indication that the skill supports other languages or that the locale restriction is intentional. This appears to impose a specific language/locale in configuration data without user opt-in, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs that voice-direction information be written in a specific Chinese-named file, 视觉设定.md, as an authoritative location. Because this is framed as a fixed language/file convention rather than an optional locale choice or region-specific requirement, it constitutes a natural-language locale policy constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

These lines require references to use visible IDs within 视觉设定.md and place audio in 输入/, embedding Chinese-language naming conventions as mandatory workflow elements. The text does not provide a user opt-in, alternative locale, or justification for restricting the workflow to this locale-specific convention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L086 states that the display name "必须含中文", which imposes a specific language requirement in natural-language instructions. This is a locale/language constraint without any user opt-in or clear region-specific justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions in Chinese and does not indicate user opt-in for that language, offer alternative locales, or explain that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language instructions only in Chinese, which effectively forces a specific language for users or maintainers consuming the skill guidance. Under the policy, locale or language restrictions should be opt-in or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This file presents all operational guidance in a single forced language, which can violate language/locale policy when users are not given an opt-in or alternative. The content does not indicate that the skill is limited to a Chinese-only audience or compliance context that would justify the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The JSONL records include Chinese path and artifact names such as "设定集" and "剧集" throughout the file. For a file applicable across general contexts, this embeds a specific language/locale without any accompanying indication that users can choose or opt into that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Across the file, key natural-language fields such as artifact paths, evidence, rationale, and creator questions are written in Chinese, which indicates a fixed language/locale for the skill data examples. The file does not state that this locale is optional, user-selected, or justified as a region-specific constraint, so it may violate the language/locale policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.