Back to skill

Security audit

story-short-write

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese short-story writing skill that creates local draft files and runs local style checks, with no hidden network, credential, or destructive behavior found.

Install this if you want a Chinese web-fiction drafting workflow that works in local project files. Expect it to create and edit story drafts, outlines, and reference folders, and to run local Node.js style checks. Keep revenge or abuse prompts fictional and non-instructional, and review changes before running it on valuable drafts because one included utility rewrites punctuation in specified files.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The file explicitly normalizes and operationalizes revenge, privacy abuse, doxxing, sexual humiliation, and extreme retaliatory violence as desirable story beats without any embedded safety boundary, warning, or de-escalation guidance. In a creative-writing skill, this increases the chance the agent will generate harmful abuse fantasies, privacy-violating scenarios, or revenge-focused content in response to ambiguous user prompts, making the skill context more dangerous rather than less.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This file hard-codes Chinese-language genre instructions and examples across the entire skill artifact without indicating any user-language negotiation or opt-in. While not a classic security flaw, it is a real policy/quality vulnerability because it can override user expectations, reduce accessibility, and cause the agent to ignore or mishandle requests in other languages.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This reference file is entirely written in Chinese and supports a skill whose metadata and trigger phrases are also Chinese, so the skill effectively constrains interaction to one language without an explicit user choice mechanism. While not a classic security flaw, it is a genuine policy/compliance issue because it can override user language preference and reduce transparency or usability for non-Chinese-speaking users.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow explicitly instructs the agent to write content directly into files without any requirement to notify the user, obtain confirmation, or clearly disclose that persistent filesystem changes will occur. In an agent setting, silent file writes can surprise users, overwrite existing work, or create unintended artifacts, especially because this skill appears designed to generate and iteratively modify multiple working documents.

Static analysis

No suspicious patterns detected.