Back to skill

Security audit

长篇原著分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local workflow for analyzing user-provided novels into short-drama adaptation notes, with disclosed file outputs and no evidence of hidden network, credential, persistence, or destructive behavior.

Install only for projects where you are comfortable letting the agent read the novel files you provide and create local analysis outputs. Confirm you have rights to analyze the source material, and review triage.md before allowing a full-book analysis unless you explicitly want the whole pipeline run at once.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个面向用户的小说拆解与改编价值分析技能,重点在结构化分析产物与改编判断,并强调只读。实际提供的代码片段却只是 selftest.py,自身并不分析用户提供的小说,也不输出所声明的多种分析结果;它只是为底层 novel_index 模块做离线自测,包含临时文件写入、索引写入、校验和抽样测试。虽然其中涉及章节索引这一声明中的一小部分相关能力,但从主要目的和实际行为看,这段代码与声明用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill explicitly instructs reading user-provided files and writing multiple outputs under project directories, but it does not declare any tool scope such as allowed tools or path restrictions. Without an explicit permission boundary, a runtime may grant broader file read/write capability than intended, increasing the chance of unintended access or modification outside the skill's stated workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The display name, short description, and default prompt are all written exclusively in Chinese, which indicates a fixed language/locale experience. There is no visible opt-in, alternative language option, or justification that this skill is intentionally limited to Chinese-speaking users or a region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown skill file forces a specific language for all instructions and outputs, which is a natural-language locale constraint. The file does not indicate that Chinese is optional, user-selected, or required for a clearly region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document’s instructions and headings are fully Chinese-language, and there is no indication that users may choose another language or that the skill is intentionally restricted to Chinese-language content. This can violate language/locale policy when a skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all instructions in a single enforced language, which can violate language/locale policy when users are not given an opt-in or alternative. The document does not indicate that the skill is region-specific or that Chinese is a justified requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill file is written in Chinese and presents its operating contract only in that language, with no indication that users may choose another language or that the skill is restricted to a Chinese-language context. Under the policy, a language or locale constraint should either be optional for the user or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.