Back to skill

Security audit

story-deslop

Security checks for vulnerabilities and agentic risk

Overview

This Chinese web-novel polishing skill edits local writing files and can keep disclosed local author-style memory, but I found no hidden network, credential, destructive, or deceptive behavior.

Install this only if you want a Chinese web-novel editing skill that may directly rewrite supplied manuscript files and may keep local author-style preferences in the workspace. Review or delete .story/作者记忆 if you do not want persistent writing-preference history retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The declared purpose is prose polishing, but the skill also performs persistent author-memory queries and writes, file mutation, and workflow/state management outside that narrow description. This mismatch undermines informed consent and can lead users to invoke a text-editing skill without realizing it stores cross-session data or modifies local project state.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The declared purpose is prose polishing, but the skill also performs persistent author-memory queries and writes, file mutation, and workflow/state management outside that narrow description. This mismatch undermines informed consent and can lead users to invoke a text-editing skill without realizing it stores cross-session data or modifies local project state.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The declared purpose is prose polishing, but the skill also performs persistent author-memory queries and writes, file mutation, and workflow/state management outside that narrow description. This mismatch undermines informed consent and can lead users to invoke a text-editing skill without realizing it stores cross-session data or modifies local project state.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The declared purpose is prose polishing, but the skill also performs persistent author-memory queries and writes, file mutation, and workflow/state management outside that narrow description. This mismatch undermines informed consent and can lead users to invoke a text-editing skill without realizing it stores cross-session data or modifies local project state.

Ae1

High
Category
analysis-evasion
Content
node scripts/check-ai-patterns.js --check --fail-on=blocking <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/check-ai-patterns.js --check --fail-on=blocking <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/check-ai-patterns.js --check --fail-on=blocking <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/check-ai-patterns.js --check --fail-on=blocking <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/check-degeneration.js --check <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/check-degeneration.js --check <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/check-degeneration.js --check <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/normalize-punctuation.js <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/normalize-punctuation.js <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/normalize-punctuation.js <正文文件...>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file implements a persistent author-memory system with journaling and profiling, which is materially unrelated to the declared skill purpose of removing AI-writing traces from text. In a text-cleaning skill, unexpected stateful memory collection expands data exposure and trust boundaries, creating a hidden capability to retain user content, preferences, and workflow history beyond the immediate transformation task.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The code establishes workspace-level persistent storage for 'author memory' under .story/作者记忆, enabling long-term profiling of user preferences and captured evidence. For a de-AI-texting skill, this is an unjustified data-retention mechanism that can silently accumulate sensitive writing habits, excerpts, and editorial history, increasing privacy and misuse risk.

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent to read and write workspace files and execute shell commands, but it declares no explicit tool scope or permissions boundary. That increases the blast radius if the skill is triggered unexpectedly or misused, because the runtime may grant broader capabilities than users realize.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases include broad natural-language activators like '这篇太AI了' and '网文去AI味', which can overlap with ordinary conversation rather than an intentional tool invocation. Because the skill can read/write files and invoke subprocesses, accidental activation could cause unintended analysis, file edits, or state mutation.

Ssd 3

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to persist and reuse cross-session author style preferences, but it does not clearly limit what may be captured or exclude sensitive personal content embedded in writing samples. Over time this can create a durable profile of user habits or leak private material into future sessions without fully informed consent.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The document is entirely written as mandatory guidance in Chinese and frames its style rules as the default writing mode to be followed. This can violate language/locale policy when a skill forces a specific language or locale without explicitly giving the user a choice or documenting a justified regional constraint.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This skill reference forces a specific language/locale in its natural-language instructions, which can violate organizational language-choice policy when no user opt-in or regional justification is provided. The file contains no indication that Chinese is optional, user-selected, or required for a China-specific workflow.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
This file contains natural-language instructions that prescribe specifically Chinese writing norms, such as preserving "中文的自然冗余," rather than presenting them as optional or context-limited. Because the policy applies to all file types and disallows forcing a language or locale without opt-in, this is a language-policy issue.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file defines user-facing labels entirely in Chinese, and later renders Markdown views and summaries using those strings. This imposes a specific language/locale on all users of the skill without opt-in or any documented regional limitation, which matches the language/locale policy violation criteria.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The rendered views and journal functionality expose historical transactions, revision summaries, and memory changes that are unrelated to the advertised text-cleaning function. This creates unnecessary retention and visibility of prior user interactions, which can leak sensitive writing preferences or quoted content to anyone with workspace access.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The usage/help text and the detection logic are built specifically around Chinese prose patterns, with user-facing messages and regexes targeting only Chinese text forms. This effectively forces a specific language/locale behavior without offering a language choice or clearly documenting that the tool is intentionally limited to Chinese-language content.

Static analysis

No suspicious patterns detected.