Back to skill

Security audit

短剧资产图片提示词

Security checks for vulnerabilities and agentic risk

Overview

This is a specialized prompt-writing and validation skill with no evidence of hidden network access, credential use, persistence, or media-generation behavior.

Install this if you want a Chinese short-drama image-prompt workflow that may read and update project creative files. Actual media generation is delegated to another skill with explicit confirmation, and I found no evidence of hidden external calls or credential handling.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明强调的是“为用户编写或修改可复制的图片提示词 Markdown”,属于内容创作/编辑能力;而实际代码并不生成、修改或润色任何提示词文本,也没有面向用户请求生成角色/场景/道具提示词。它的主功能是离线校验 prompt spec 文件是否符合规则,是一个验证/审计工具。虽然代码确实与图片提示词领域相关,也符合“不生成图片、不调用供应商”的部分表述,但其核心行为与声明的主要用途存在明显偏差,属于 materially different primary purpose。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description says the skill should help compose or revise image prompt Markdown for various visual design artifacts, explicitly not generating images or calling vendors. The actual code does not author prompts for users at all; it is a developer-facing test harness for a validator module. Its primary behavior is loading fixture data and checking that validation errors occur for invalid structured records. While this is related to image-prompt specifications in a broad sense, it is materially different from the declared end-user function of writing/editing prompt Markdown. No external provider calls are present, which is consistent with the description, but the main purpose and capabilities do not match.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/stage-contract.md (reported line 23)May include surrounding context.

md
| IMG-06 | structural_invariant | Edit prompts declare exact target, changes, preserve set, and expected continuity impact. |
| IMG-07 | structural_invariant | Readable text cannot coexist with a global no-text constraint. |
| IMG-08 | reviewed_invariant | A claim about reference pixels requires a creator/reference-owner description or authorized input-reference observation bound to the inspected bytes; otherwise admission stays unresolved, and a negative prompt cannot stand in for evidence. |
| IMG-09 | reviewed_invariant | Each reference states its purpose, what may be copied, and what must not be copied; a composition-, scale-, or effect-only reference cannot redefine identity, content, text, or story state. |
| IMG-10 | reviewed_invariant | Views of one Location in the same time/weather state share key-light source, colour-temperature relation, and contrast direction; any difference cites a recorded cause and its delta. |
| IMG-11 | reviewed_invariant | A lookdev frame binds accepted visual direction and production profile across a declared character-expression, core-location, or high-pressure test axis; a high-pressure frame also binds exact screenplay blocks for story state and information permission, while style references may control only declared surface treatment and never identity, fixed geography, story state, cast count, or prop text. |
| IMG-12 | reviewed_invariant | Each real input reference has a stable `REF-...` slot binding explicit order, a visible project-relative path or other unambiguous artifact locator, a Chinese label, and may-control/must-not-control scope. Reordering preserves slot identity; replacing media explicitly revises that slot's locator. `IMG-...` remains reserved for image-prompt headings. |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all operational guidance in Chinese, and it does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file title and the entire skill guidance are written in Chinese, with no indication that users may choose another language or locale. Under the policy rule, a skill that imposes a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill file is written as prescriptive guidance in Chinese and does not indicate that users may choose another language or locale. Under the policy rule for natural-language constraints, this is a language-policy issue because the document imposes a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains user-facing natural-language instructions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is restricted to a Chinese-language context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions, examples, and review criteria only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in or a documented region-specific justification is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill states that prompt text defaults to en when short-drama.json is absent and explicitly forbids inferring language from the creator's language. This imposes a specific language choice without asking the user, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file presents its instructions primarily in Chinese while also embedding untranslated English terms such as 'accepted layout', 'orientation', and policy labels. Because the document does not state that the skill is region- or language-specific or offer a user language/locale choice, it may impose a language/locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's natural-language instructions are entirely in Chinese and do not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This file is entirely written for Chinese-language use, with required labels such as a Chinese label for references and Chinese vocabulary in the closed set. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.