Back to skill

Security audit

短剧开发

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese short-drama development workflow with disclosed, purpose-aligned project files and local indexing helpers.

Install this for Chinese-language short-drama development workflows. Expect it to read source material you provide and create or update project-development files such as briefs, story engines, episode indexes, and episode maps; review the companion @worldwonderer/short-drama skill separately if you install it too.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is substantively the same class of issue: the skill presents itself as a story-development tool while also directing offline testing, file-level episode indexing, text extraction, and source-drift checks. Hidden or under-declared operational capabilities reduce transparency and can bypass user expectations about what data the skill will access and transform.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding is substantively the same class of issue: the skill presents itself as a story-development tool while also directing offline testing, file-level episode indexing, text extraction, and source-drift checks. Hidden or under-declared operational capabilities reduce transparency and can bypass user expectations about what data the skill will access and transform.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises file-reading and file-writing related workflows, including generating project artifacts and mechanical indexes, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity: the runtime may permit broader filesystem access than the skill actually needs, increasing the chance of unintended reads or writes if invoked in a sensitive workspace.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description contains broad, everyday phrases that could match many normal creative or planning requests, causing the skill to be invoked when the user did not intend it. Overbroad activation increases the likelihood of unnecessary file access, document creation, or workflow routing in contexts where the user only wanted general discussion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L003 明确写明将‘中文小说、短剧或漫剧想法’发展成相关产物,整体文件也仅提供中文交互说明,但未说明是否支持用户选择其他语言。若该技能在更广泛环境中被调用,这种默认且未提供 opt-in 的语言约束可能构成语言/locale 政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name, description, and default prompt are all written only in Chinese, which indicates a fixed language/locale experience. The file does not offer user opt-in, language selection, or any justification that this skill is intended only for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The example embeds Chinese-language path segments and descriptive text such as "项目开发", "输入", and multiple Chinese prose fields, which suggests a fixed language/locale expectation in the skill artifact. Because there is no accompanying indication that users may choose another language or that the locale restriction is intentional and justified, this may violate the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire template is written in Chinese and instructs users to fill out all briefing fields in that language context, but it does not offer any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill template and instructions are written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains all user-facing guidance in Chinese, and nowhere indicates that users may choose another language or that the content is intentionally limited to Chinese-speaking users. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document title and all instructional content are written in Chinese, and nowhere in the file is there an indication that language is selectable or that the skill is intentionally limited to a Chinese-language workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses Chinese throughout and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy provided, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructional content in a single language and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This file presents all instructions and examples exclusively in Chinese, and nowhere indicates that Chinese is optional, user-selected, or required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file contains user-facing operational instructions exclusively in Chinese, which can amount to a language/locale policy violation when no opt-in or alternative language path is provided. The policy explicitly allows fixed locale only when the constraint is documented and justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and the entire document are written in Chinese, and there is no indication that the skill supports multiple languages or that Chinese is an intentional, documented regional restriction. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Chinese and provides no indication that language selection is optional or limited to a justified region-specific use case. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill contract is written in Chinese and provides no indication that another language may be used or that Chinese is a justified region-specific requirement. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains natural-language instructions exclusively in Chinese, beginning with the title on L001, and nowhere indicates that users may opt into another language or that the locale restriction is required. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSONL template includes hard-coded Chinese placeholder strings such as "<人物/观众各自知道到哪一步>" and "<本集若有误述,写哪条条款被误述及埋了什么线索>". This introduces a locale-specific requirement in the skill artifact without any indication that Chinese is optional or that the skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all instructional content in Chinese and does not indicate that the skill is region-specific or that users may opt into another language. Under the natural-language policy rule, forcing a specific language without user choice can be a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.