Back to skill

Security audit

短剧审查

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent short-drama review helper with disclosed local review guidance and offline validators; I found no hidden network, credential, persistence, or destructive behavior.

Install this only for Chinese-language short-drama review workflows where you are comfortable letting the agent read the named project files and, when needed, write concise review Markdown. Treat the bundled Python scripts as optional offline validation/maintenance tools, not as part of normal creative review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This duplicate mismatch finding similarly indicates the skill may actually run offline self-tests and validate JSON/JSONL review records instead of performing the advertised short-drama review task. In a review workflow, such mismatch can conceal operational behavior, confuse audit trails, and result in incomplete or incorrect security/content review outcomes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This duplicate mismatch finding similarly indicates the skill may actually run offline self-tests and validate JSON/JSONL review records instead of performing the advertised short-drama review task. In a review workflow, such mismatch can conceal operational behavior, confuse audit trails, and result in incomplete or incorrect security/content review outcomes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says to use the skill when the user提出“审稿/检查剧本”“检查资产或连续性”“检查图片/视频提示词”等,这些短语较宽泛,可能与普通协作对话重叠。The manifest does not provide exclusion conditions or a tighter invocation context, increasing the risk of unintended activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational guidance in Chinese, and it does not indicate that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking context. That creates a natural-language policy concern because it effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill guidance is written only in Chinese and does not indicate that language selection is optional or configurable. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale policy violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires deleted content to be listed under the Chinese heading ## 被删的强钩子, which imposes a specific language choice in the review artifact. The file does not offer a language option or explain a region-specific need, so this is a natural-language locale policy violation under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L029 states that voice direction is reviewed only when 视觉设定.md records it, and the document repeatedly relies on Chinese-language filenames and terms throughout the rubric. This natural-language framing imposes a specific language/locale convention without offering an alternative or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill rubric is written in Chinese and provides no indication that language selection is optional or limited to a documented Chinese-only context. Under the policy rule, a skill that implicitly requires a specific language without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file includes a Chinese heading (目录) and later substantial Chinese-only operational guidance, which imposes a specific language context on users without any opt-in or explanation. Under the policy rule, forcing a language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Lines 176-199 switch into Chinese for substantive review instructions and checklist content, but the document does not explain that it is region-specific or offer an alternate language. This creates an undocumented language constraint for users of the skill reference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON example contains Chinese-language path/content strings, which may impose a specific language context without any documented user opt-in or locale justification. Under the policy rule, forcing a specific language in natural-language content can be a locale-policy issue when no choice is offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The placeholder strings for evidence and rationale are written only in Chinese, and the file does not indicate that the skill is region-specific or that users can choose a language. This can violate the language/locale policy for natural-language content across file types.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The JSON template includes artifact path values using Chinese-language directory names in string literals, but the file provides no indication that this locale choice is optional, user-selected, or tied to a documented region-specific requirement. Because SQP-3 applies to all file types and covers forced language or locale behavior in config values, this is a mild natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L003 uses a Chinese heading ("目录") in an otherwise predominantly English document, and later lines also include Chinese text such as at L283 and L291. This creates a language/locale inconsistency without any stated user opt-in or justification for a bilingual or Chinese-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.