Back to skill

Security audit

短剧分镜与冻结关键帧

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese short-drama storyboarding assistant that works on project storyboard files and does not show hidden network, persistence, or destructive behavior.

Install only for projects where the agent may read and edit the relevant short-drama screenplay, visual-setting, storyboard, and reference-image files. If your project is not Chinese-language, set or clarify the prompt language before generating deliverables.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个创作/整理型技能:把剧本和视觉设定写成分镜 Markdown,并协助镜头设计、方案比较和关键帧提示词撰写。实际代码则是纯检查器,且文件头明确说明“reads accepted creator files and writes nothing”。其主要功能是对既有结构化产物做规则校验:SHT-16 时长统计、SHT-17 关键帧边界绑定、SHT-05 边界描述不得仅回指、SHT-01 剧本块覆盖与 disposition 完整性。这与“生成分镜 Markdown”这一主目的明显不符。虽然声明里提到可“检查…连续性”,与 boundary/continuity 检查有部分相关,但代码覆盖的是机械一致性校验而非面向用户的分镜生成与设计,因此存在实质性 description-behavior mismatch。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to read and update project files such as 剧本.md and 分镜.md, but it does not declare any explicit tool scope or allowed-tools policy. That creates an authorization gap where file read/write behavior exists without clear limitation, increasing the chance of over-broad file access or unintended modification of unrelated project content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Defaulting prompt output language to English without user confirmation can cause the generated keyframe prompts to diverge from the user's expected language and project conventions. In a creative production pipeline, this can lead to silent prompt misuse, review failures, or incorrect downstream generation settings, especially when language carries important semantic nuance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSONL template contains multiple Chinese-only artifact paths and example values such as '设定集', '剧集', and Chinese instructional text in placeholders. Because the file provides no indication that Chinese is optional or required for a region-specific workflow, it appears to enforce a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains natural-language instructions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written in Chinese and describes the skill behavior in a way that presumes Chinese-language interaction, without indicating any fallback, user choice, or localization handling. This can cause the agent to ignore a user's preferred language, degrade usability, and lead to misunderstanding of safety-critical storyboard constraints or outputs for non-Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This reference material presents core operational guidance partly in Chinese and partly in English, which effectively imposes a language expectation on the user without opt-in. The file does not explain that it is intended for a Chinese-speaking workflow or offer an alternative language path, so it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this locale. Under the language/locale policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill example, including headings and instructional content, is written only in Chinese and does not indicate that this is a locale-specific or opt-in language mode. Under the policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill contract is written in Chinese and uses Chinese field names and file conventions such as 分镜.md and 视觉设定.md, with no indication that other languages are supported or that the user can opt into this locale. That creates a natural-language policy concern because it effectively imposes a specific language on skill use without an explicit choice or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The display name, description, and default prompt are all written exclusively in Chinese, which suggests the skill is intended to operate in a fixed language. There is no indication in this file that users can opt into another language or that the Chinese-only constraint is required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file contains multiple natural-language strings and path components in Chinese, such as artifact names and placeholder text, with no indication that the skill supports alternative languages or that the locale restriction is intentional. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation, even in example/config data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The JSON template includes path examples under the Chinese directory name "剧集" in artifact fields, which embeds a specific language/locale convention in the skill asset. There is no indication in this file that alternative language/locale values are supported or that this locale is required for a region-specific use case.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSONL template contains multiple unconstrained placeholders such as "", "", and "" but provides no explicit constraints or negative examples for what values are valid. In a manifest-like template, that ambiguity can lead to overly broad or unintended matching/use because the activation or selection scope is not clearly bounded.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The placeholder text for the "reason" field is written only in Chinese ("导演职责怎样被拆开、合并或恢复"), which imposes a specific language in a configuration artifact. The file does not indicate that language selection is optional or region-specific, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-like example contains generic placeholder values and free-form fields, but provides no indication of when this template should be used versus not used. Under the vague-trigger rule for manifest files, the lack of specificity or negative constraints can make invocation scope ambiguous for downstream consumers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The language policy states that prompt body language follows prompt_language, and defaults to en when no project configuration exists. This is a natural-language locale policy that can force a specific language choice absent explicit user selection, which matches the policy-violation category for language or locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that the user can choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.