Back to skill

Security audit

短剧创作路由

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local short-drama project manager and dashboard whose file access and background localhost server fit its stated purpose.

Install this only for a Chinese-language short-drama workflow you want managed through local project files. It may create and edit files under the selected project, export snapshots, and launch a background localhost dashboard; use the documented --status and --stop commands when you no longer need the dashboard, and avoid selecting a workspace containing unrelated private material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个项目编排/路由型 skill,强调创建或继续项目、查看进度、Dashboard、Look Development 与跨阶段决策;而代码是一个命令行验证器,核心功能是解析并校验五份 Markdown 文档及其引用资源的一致性。它会读取文件系统中的文档和引用文件、检查路径安全性、解析正则语法、验证镜头与场景映射、音频/图片参考、视觉设定覆盖、连续性锁、生成方式等。这与“初始化项目、继续项目、打开 dashboard、导出资料、做创作决策”的主目的明显不同,属于实质性描述-行为不一致。

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · assets/dashboard/app.js (reported line 929)May include surrounding context.

js
if (!ask) return "";
  return `<button class="btn sm ${primary ? "primary" : ""}" type="button" data-copy="${esc(ask)}" data-copy-label="已复制,去对话里发送">${icon("copy")}${label}</button>`;
}
/** Distance from a target value, stated without judging it: the profile gives the target, not a tolerance. */
function gapText(value, goal) {
  const d = Math.round((value - goal) * 10) / 10;
  return d === 0 ? "与目标相同" : `${d > 0 ? "多" : "少"} ${num(Math.abs(d))} 秒`;

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/creator_markdown_check.py (reported line 99)May include surrounding context.

python
VOICE_RECORD_PATH_RE = re.compile(
    r"([^(;\n]+?\.(?:" + "|".join(AUDIO_SUFFIXES) + r"))(?=(|$)", re.IGNORECASE
)
# The screenplay's dialogue grammar, mirrored from the write skill's
# screenplay_index.py (DIALOGUE_RE, and TAG_RE + VOICE_TAG_BODY_RE for [VO] and
# [OS]). Each is matched against a whole paragraph, so a line that wraps onto
# the next physical line is still one line of dialogue.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/creator_markdown_check.py (reported line 304)May include surrounding context.

python
if not lines or any(not line.startswith(">") for line in lines):
        return None
    prompt = "\n".join(line[1:].lstrip() for line in lines).strip()
    return prompt or None


def _copyable_prompt_cause(

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/creator_views.py (reported line 379)May include surrounding context.

python
if not lines or any(not line.startswith(">") for line in lines):
        return None
    prompt = "\n".join(line[1:].lstrip() for line in lines).strip()
    return prompt or None


def _copyable_prompt_cause(

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/creator_views.py (reported line 400)May include surrounding context.

python
if not lines or any(not line.startswith(">") for line in lines):
        return None
    prompt = "\n".join(line[1:].lstrip() for line in lines).strip()
    return prompt or None


def _copyable_prompt_cause(

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to invoke shell commands, read and write project files, and start a detached local dashboard server, but it does not declare any tool scope or allowed-tools restrictions. That creates an overprivileged execution surface where the runtime may permit broader filesystem, shell, or network actions than users expect, increasing the chance of misuse, data exposure, or unintended persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default prompt is framed broadly enough to encourage invocation across several distinct actions such as initialization, recovery, continuation, and dashboard management without stating concrete boundaries or eligibility checks. In an agent-routing context, this can cause over-triggering, misrouting, or unintended access to file-system-backed project state when the user's request is ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains pervasive user-facing strings and labels in Chinese, including core actions like 编辑原文, 保存, 搜索, and status/error messages. The skill does not present any opt-in, locale selection, or documented justification for restricting the interface to a specific language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/dashboard/app.js (reported line 1412)May include surrounding context.

js
.copybar { position: sticky; top: calc(var(--zs-topbar-height) + var(--zs-tabbar-height) + var(--zs-space-2h)); z-index: 5; display: flex; align-items: center; gap: var(--zs-space-3h); padding: var(--zs-space-2h) var(--zs-space-3h); margin-bottom: var(--zs-space-3h); box-shadow: var(--zs-shadow-sm); flex-wrap: wrap; }
.copybar .bar { width: 160px; margin: 0; }
.copybar .lbl-long { font-size: var(--zs-text-12); margin-left: auto; }
.plist { display: grid; gap: var(--zs-space-2h); }
.pcard { display: grid; grid-template-columns: 200px minmax(0, 1fr) auto; gap: var(--zs-space-4h); padding: var(--zs-space-3h) var(--zs-space-4); align-items: start; scroll-margin-top: 180px; }
.pcard > div { min-width: 0; }
.pcard.copied { background: linear-gradient(90deg, var(--zs-ok-wash), transparent 40%), var(--zs-surface); }

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/dashboard/styles.css (reported line 536)May include surrounding context.

css
.copybar { position: sticky; top: calc(var(--zs-topbar-height) + var(--zs-tabbar-height) + var(--zs-space-2h)); z-index: 5; display: flex; align-items: center; gap: var(--zs-space-3h); padding: var(--zs-space-2h) var(--zs-space-3h); margin-bottom: var(--zs-space-3h); box-shadow: var(--zs-shadow-sm); flex-wrap: wrap; }
.copybar .bar { width: 160px; margin: 0; }
.copybar .lbl-long { font-size: var(--zs-text-12); margin-left: auto; }
.plist { display: grid; gap: var(--zs-space-2h); }
.pcard { display: grid; grid-template-columns: 200px minmax(0, 1fr) auto; gap: var(--zs-space-4h); padding: var(--zs-space-3h) var(--zs-space-4); align-items: start; scroll-margin-top: 180px; }
.pcard > div { min-width: 0; }
.pcard.copied { background: linear-gradient(90deg, var(--zs-ok-wash), transparent 40%), var(--zs-surface); }

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest sets "language": "zh-CN" and "prompt_language": "en" as fixed values, but there is no indication in this file that the user can opt into or change these locale choices. Per the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document instructs that video prompts should 'use the project's prompt language' directly, which imposes a language choice in the generated output. While some earlier lines describe behavior when the prompt body language is not Chinese, this file does not clearly offer the user a language or locale choice or frame the constraint as an opt-in policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These lines prescribe default output languages and fallback locale behavior, including defaulting image/keyframe content to en when short-drama.json is absent. This is a natural-language locale policy constraint presented as mandatory behavior, without offering the user a language choice or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill reference is written in Chinese and does not indicate that language choice is optional or limited to a justified region-specific context. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Chinese and includes prescriptive instructions and terminology without offering a language choice or stating that the skill is intentionally limited to a Chinese-language or region-specific context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document explicitly requires a '中文名称' and provides the workflow and examples entirely in Chinese, which imposes a language constraint on users. There is no opt-in, alternative locale path, or justification that this skill is limited to a Chinese-only regulatory or regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The text states '输出语言...见 契约与所有权', indicating the skill enforces a predefined output-language rule. Under the policy, forcing a specific language or locale without offering user choice or opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code imposes a specific locale by returning en as the fallback prompt language whenever short-drama.json is absent, invalid, or lacks the relevant fields. Under the stated policy, forcing a language without explicit user opt-in is a natural-language policy violation unless the constraint is clearly justified as a region-specific tool or the user is given a choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring says "Nothing here reads files; the server hands in text it read safely," which asserts file-free behavior for the module. However, _load_checker() resolves a filesystem path and executes creator_markdown_check.py via spec.loader.exec_module, which is a direct code-loading file read from disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains natural-language strings and identifiers that require Chinese-language filenames such as 剧本.md, 视觉设定.md, and 分镜.md, and later emits Chinese-only user-facing parsing errors. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains multiple hard-coded user-facing status and warning strings in Chinese, such as the discovery warning at L0524, with similar strings throughout the file. Because the skill does not provide an opt-in or locale-selection mechanism for these messages, it imposes a specific language on users and violates the language/locale policy.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/dashboard_server.py (reported line 1861)May include surrounding context.

python
else:
        options["start_new_session"] = True
    try:
        return subprocess.Popen(
            command,
            stdin=subprocess.DEVNULL,
            stdout=log,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains multiple natural-language error strings that force Chinese output, such as at L0767-L0774 and L0791-L0799. Because the skill is not clearly documented as region-specific and does not provide user opt-in or locale selection for these messages, it violates the language/locale policy constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The user-facing display name and descriptions are entirely in Chinese, with no indication that language is selectable or that the skill is intended only for a Chinese-language audience. This can violate language/locale policy when a skill imposes a specific language without user opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/creator_views.py:45

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/dashboard_server.py:138