Back to skill

Security audit

story-long-scan

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does disclosed public web-novel ranking collection, but it includes guidance for fake engagement and ranking manipulation that users should review carefully.

Install only if you are comfortable with a skill that runs local scraper scripts, opens targeted novel-platform pages through browser automation, and writes report files. Treat its platform-growth advice cautiously: avoid fake engagement or ranking-manipulation tactics, and verify any platform rules through official channels before acting on recommendations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared function is broad market analysis across several novel platforms, but the identified implementation may only automate Qimao collection and export structured results. Hidden narrowing plus undisclosed browser automation increases review blind spots and can cause the skill to be invoked under false expectations.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The declared function is broad market analysis across several novel platforms, but the identified implementation may only automate Qimao collection and export structured results. Hidden narrowing plus undisclosed browser automation increases review blind spots and can cause the skill to be invoked under false expectations.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The declared function is broad market analysis across several novel platforms, but the identified implementation may only automate Qimao collection and export structured results. Hidden narrowing plus undisclosed browser automation increases review blind spots and can cause the skill to be invoked under false expectations.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The declared function is broad market analysis across several novel platforms, but the identified implementation may only automate Qimao collection and export structured results. Hidden narrowing plus undisclosed browser automation increases review blind spots and can cause the skill to be invoked under false expectations.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared function is broad market analysis across several novel platforms, but the identified implementation may only automate Qimao collection and export structured results. Hidden narrowing plus undisclosed browser automation increases review blind spots and can cause the skill to be invoked under false expectations.

Ae1

High
Category
analysis-evasion
Content
1. 选择平台脚本;起点直接运行 `scripts/qidian-rank-scraper.js`,番茄/七猫/晋江等按需启动 browser-cdp
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
1. 选择平台脚本;起点直接运行 `scripts/qidian-rank-scraper.js`,番茄/七猫/晋江等按需启动 browser-cdp
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
1. 选择平台脚本;起点直接运行 `scripts/qidian-rank-scraper.js`,番茄/七猫/晋江等按需启动 browser-cdp
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
nk/{channel}_{type}_{cat_id}`,channel 0=女频/1=男频,type 1=新书榜/2=阅读榜。番茄列表页有字体反爬,须用 `scripts/fanqie-rank-scraper.js` 从详情页多策略解码书名/作者/题材/评分/标签/简介,配合 browser-cdp 使用:
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
nk/{channel}_{type}_{cat_id}`,channel 0=女频/1=男频,type 1=新书榜/2=阅读榜。番茄列表页有字体反爬,须用 `scripts/fanqie-rank-scraper.js` 从详情页多策略解码书名/作者/题材/评分/标签/简介,配合 browser-cdp 使用:
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
nk/{channel}_{type}_{cat_id}`,channel 0=女频/1=男频,type 1=新书榜/2=阅读榜。番茄列表页有字体反爬,须用 `scripts/fanqie-rank-scraper.js` 从详情页多策略解码书名/作者/题材/评分/标签/简介,配合 browser-cdp 使用:
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
nk/{channel}_{type}_{cat_id}`,channel 0=女频/1=男频,type 1=新书榜/2=阅读榜。番茄列表页有字体反爬,须用 `scripts/fanqie-rank-scraper.js` 从详情页多策略解码书名/作者/题材/评分/标签/简介,配合 browser-cdp 使用:
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
**晋江采集目标**(`scripts/jjwxc-rank-scraper.js`,默认列表 + 详情两步走):
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
**晋江采集目标**(`scripts/jjwxc-rank-scraper.js`,默认列表 + 详情两步走):
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
**晋江采集目标**(`scripts/jjwxc-rank-scraper.js`,默认列表 + 详情两步走):
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
**晋江采集目标**(`scripts/jjwxc-rank-scraper.js`,默认列表 + 详情两步走):
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
**晋江采集目标**(`scripts/jjwxc-rank-scraper.js`,默认列表 + 详情两步走):
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| [scripts/qimao-rank-scraper.js](scripts/qimao-rank-scraper.js) | 七猫榜单采集(大热/新书/完结等),tab 切换(失败重试)+滚动加载,按 bookId 取书名回填作品页链接,带连通性自检+链接/热度命中率标注 |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| [scripts/ciweimao-rank-scraper.js](scripts/ciweimao-rank-scraper.js) | 刺猬猫榜单采集(点击/收藏/月票等),单页 9 榜提取,按 bookId 归一书名回填作品页链接,带连通性自检+空结果重试+链接命中率标注 |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The education row includes a derogatory socioeconomic example ('大学生 vs 初中辍学') and frames literacy/logic expectations through education status. This is more dangerous than a generic segmentation heuristic because it normalizes demeaning class-coded assumptions and could drive discriminatory content targeting or exclusionary treatment of less-educated users.

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill instructs the agent to use networked scraping and environment-backed script execution, but it does not declare any explicit tool scope or allowed-tools boundary. That creates an authorization ambiguity where the runtime may permit broader access than users expect, increasing the chance of unintended outbound requests or local execution side effects.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases include broad natural-language prompts such as generic questions about what is popular, which makes accidental or opportunistic activation more likely. In this skill, unintended activation is more concerning because activation can lead to network scraping, browser automation, and file creation rather than a simple text-only response.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file presents all instructions and examples exclusively in Chinese, and there is no natural-language indication that the skill is region-specific or that users may opt into another language. Under the language/locale policy rule, forcing a single language without user opt-in is a policy concern.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
SQP-3 applies to all file types and covers language or locale policy violations. This guide presents all instructions and content in Chinese only, with no indication that users can choose another language or that the skill is restricted to a Chinese-speaking or region-specific audience.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The guide includes explicit advice on manipulating platform performance signals, such as using '假追' to bridge recommendation stages and increase chances of promotion, plus process gaming to remain on ranking lists longer. In a market-analysis/publishing skill, this is dangerous because it normalizes fraudulent growth tactics and could lead users to commit platform abuse, account penalties, reputational harm, or unfair market distortion.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/cdp-utils.js:88