Back to skill

Security audit

短剧写作

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese short-drama writing skill with optional local validation helpers, and I found no hidden persistence, network access, credential use, or destructive behavior.

Install this if you want a Chinese short-drama screenplay workflow. Expect it to work with local project screenplay files and, when asked for timing or checks, to run local Python helpers that create/read derived index data. Keep those helpers pointed at the intended project directory and avoid using it for non-Chinese or non-screenplay writing unless you explicitly want this format.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This variant highlights validation of recording sheets and JSONL production records against screenplay/index data, which is materially different from simple script drafting. Such hidden auditing/reporting behaviors can pull in additional files and structured metadata, broadening exposure of project internals and creating unexpected side effects for a user who only intended content editing. The context makes it moderately dangerous because the domain is content production, not system administration, so operators may not expect or constrain these checks appropriately.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This variant highlights validation of recording sheets and JSONL production records against screenplay/index data, which is materially different from simple script drafting. Such hidden auditing/reporting behaviors can pull in additional files and structured metadata, broadening exposure of project internals and creating unexpected side effects for a user who only intended content editing. The context makes it moderately dangerous because the domain is content production, not system administration, so operators may not expect or constrain these checks appropriately.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This variant highlights validation of recording sheets and JSONL production records against screenplay/index data, which is materially different from simple script drafting. Such hidden auditing/reporting behaviors can pull in additional files and structured metadata, broadening exposure of project internals and creating unexpected side effects for a user who only intended content editing. The context makes it moderately dangerous because the domain is content production, not system administration, so operators may not expect or constrain these checks appropriately.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This variant highlights validation of recording sheets and JSONL production records against screenplay/index data, which is materially different from simple script drafting. Such hidden auditing/reporting behaviors can pull in additional files and structured metadata, broadening exposure of project internals and creating unexpected side effects for a user who only intended content editing. The context makes it moderately dangerous because the domain is content production, not system administration, so operators may not expect or constrain these checks appropriately.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/screenplay_index.py (reported line 4)May include surrounding context.

python
#!/usr/bin/env python3
"""Build a byte-accurate, derived index for a short-drama Markdown screenplay.

The indexer recognizes only the screenplay grammar documented by the write
skill.  It never rewrites the screenplay and never guesses through a
split/merge revision.
"""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill text instructs the agent to read and write project files and to run local Python commands for indexing and duration estimation, but it declares no explicit tool/permission scope. That creates an authority-boundary problem: a caller may invoke a seemingly harmless writing skill that can actually access files and potentially network-capable tooling without clear consent or sandbox limits. In this context the risk is elevated by concrete operational commands and temp-file handling, even though the apparent goal is productivity rather than abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description uses broad trigger phrases such as writing, revising, polishing, continuing, and converting outlines, which can cause over-activation in contexts where users did not intend to invoke this powerful workflow. Ambiguous activation is a security issue when the skill can read/write files or run commands, because accidental invocation may expose data or create artifacts without sufficiently clear user intent. The surrounding context increases concern slightly because the same skill also contains optional command-line procedures and project-file interactions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and default prompt hard-code Chinese output rather than honoring the user's language preference. This can override user expectations, reduce usability, and in some systems cause incorrect routing or prompt conflicts, but it does not directly create a severe security primitive in this content-writing context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The default invocation phrase is very broad and can activate the skill for generic writing requests without clear user intent boundaries. In a multi-skill environment, this increases the chance of over-triggering the skill, causing unintended handling of user requests and possible context misrouting, even though the skill itself is low-risk creative writing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire template and embedded instructions are written in Chinese, which imposes a specific language/locale on skill use. The file does not offer a language choice or explain that the skill is intentionally region-specific, so this is a natural-language locale policy issue under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is natural-language guidance, and its title and body indicate the skill operates exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in is a locale-policy issue unless the file clearly documents a justified region- or language-specific scope, which it does not.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

该技能文件整体以中文编写并以中文标题直接规定内容呈现方式,但文档中未说明这是面向特定中文团队、区域或合规场景的限定要求,也未提供语言选择或用户 opt-in。根据规则,强制特定语言/locale 而无选择机制属于自然语言层面的组织政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill file is written only in Chinese and does not provide any indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title explicitly defines the format as a Chinese short-drama markdown screenplay format, which imposes a language-specific requirement. The file does not indicate that other languages are supported, optional, or that the Chinese-only constraint is a documented regional/compliance necessity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents the skill guidance exclusively in Chinese from the title onward, with no indication that users can select another language or that the skill is intentionally limited to a Chinese-language audience. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document's natural-language instructions and policy content are presented only in Chinese, which effectively forces a specific language for users or maintainers interacting with this skill artifact. The file does not provide an opt-in, alternative language, or a stated region-specific justification for this locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains multiple natural-language error and review messages in Chinese, starting here, with no mechanism to let the user choose language or locale. That creates a language policy issue because the skill's user-facing output is effectively forced to one language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The string value "项目开发/episode-map.jsonl" includes a Chinese-language path segment, which indicates a locale-specific convention embedded in the skill data. Because this file provides no opt-in, alternative locale, or justification for requiring that language/script, it may conflict with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON file appears to define a skill asset or manifest-like configuration, but it provides no invocation conditions, trigger phrases, or exclusion criteria. For manifest files, the absence of trigger specificity can make it unclear when the skill should activate versus remain inactive.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.