Back to skill

Security audit

story-short-scan

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed market-scanning tool, but one scraper reuses a logged-in admin browser session and extracts an Admin-Token to query backend management APIs.

Install only if you intentionally want a Chinese short-fiction market-scanning workflow and are authorized to use any logged-in Heiyan admin account involved. Avoid running the Heiyan scraper in shared browsers or with broad admin accounts; prefer public pages or user-provided exports where possible, and review output files before copying them into other projects.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references use of a logged-in author/admin backend and Admin-Token-authenticated internal management APIs to pull book list/detail data, which goes beyond benign public trend analysis. Accessing internal or management endpoints via an existing login session can expose non-public data and effectively turns the skill into a data-exfiltration or privileged harvesting workflow if misused.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill references use of a logged-in author/admin backend and Admin-Token-authenticated internal management APIs to pull book list/detail data, which goes beyond benign public trend analysis. Accessing internal or management endpoints via an existing login session can expose non-public data and effectively turns the skill into a data-exfiltration or privileged harvesting workflow if misused.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
3. 聚合:`node scripts/aggregate-rank.js {输出目录} --out {输出目录}/扫榜聚合.md --sparse 10 --scale short`。**主会话只读这份聚合**,要看开头与人设原文再抽样:`node scripts/aggregate-rank.js {输出目录} -

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
3. 聚合:`node scripts/aggregate-rank.js {输出目录} --out {输出目录}/扫榜聚合.md --sparse 10 --scale short`。**主会话只读这份聚合**,要看开头与人设原文再抽样:`node scripts/aggregate-rank.js {输出目录} -

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
| [scripts/dz-browse-scraper.js](scripts/dz-browse-scraper.js) | 点众短篇采集(男频/女频),用法见点众参考 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
| [scripts/heiyan-booklist-scraper.js](scripts/heiyan-booklist-scraper.js) | 黑岩书库列表采集(需登录),用法见黑岩参考 |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script explicitly requires a human to log into an admin backend, then uses that authenticated context to access management APIs for data extraction. That exceeds the declared purpose of generic trend analysis and creates a privileged-data access path that depends on reused admin credentials, which is dangerous if the skill is run in shared or loosely governed environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code reads an Admin-Token from browser cookies and repurposes it as a Bearer token for direct backend API calls. This is a credential-harvesting and session-reuse pattern: it bypasses normal user-mediated access controls, expands the blast radius of a browser login session, and could expose privileged administrative data or enable unauthorized API use if reused elsewhere.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill instructs the agent to use networked scraping, browser/CDP automation, local file writes, and script execution, but it does not declare an explicit tool/permission scope. That creates overbroad authority and makes it easier for the skill to access external sites, local environment state, or authenticated browser sessions without clear user-visible constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases include broad, natural-language expressions that may activate the skill unintentionally during ordinary conversation. Accidental invocation matters more here because the skill is capable of network/browser scraping and local file operations, so a false trigger could kick off data collection without the user's informed intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs the operator to log into a site in Chrome and then have a script extract a Bearer token from browser cookies to call backend APIs. Even if intended for legitimate scraping, handling authentication tokens this way creates credential exposure risk and enables reuse of a privileged session without clear consent, scope limits, or privacy/security warnings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains natural-language instructions and reference material exclusively in Chinese, and there is no indication that users can opt into this language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs the skill to write conclusions into a persistent markdown file and later rely on that file for subsequent workflow steps, but it does not warn users that data will be stored on disk or that re-runs may replace existing content. This creates a real transparency and integrity issue: users may unintentionally persist sensitive project notes or lose prior conclusions through overwrite behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes analyzing hot short-story data across multiple platforms such as 知乎盐言、七猫、黑岩、点众 to capture topic trends. In this file, the code is narrowly scoped to 点众阅读, visits only ishugui browse URLs, extracts book-card fields, and writes a Markdown report; there is no cross-platform aggregation or trend analysis here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The request body always sets language:'zh_TW', which forces a specific locale for fetched data. The file does not offer a user opt-in or configuration choice, and the surrounding comments do not justify this as a region-specific requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The delivery instructions tell users to copy 短篇扫榜结论.md into the project root so another command can auto-discover it, but they do not warn about possible name collisions, replacement of an existing file, or accidental exposure of internal planning data in a broader project directory. In context this is not overtly malicious, but it can still lead to unintended file overwrite or persistence in a sensitive location.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language instructions, comments, and console-facing usage guidance exclusively in Chinese. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language or locale choice is offered.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/cdp-utils.js:88