Back to skill

Security audit

story:网文工具箱路由

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese novel-writing toolbox router with local author-memory storage, a localhost dashboard, and opt-in update checks; the sensitive behaviors are mostly purpose-aligned and user-directed.

Install only if you want a Chinese-language story-writing router that can create persistent author-preference files in your workspace and run a localhost editor for selected writing projects. Treat the dashboard like a local file editor because it can save and delete supported text files, and review the update prompt carefully before allowing the global npx update command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this is the main entry for a novel-writing toolbox that routes requests to the right skill and can manage author habits, open a dashboard, and check updates. The supplied code only covers one narrow subsystem: author memory storage and maintenance. It provides CLI commands like init, commit, record, query, check, and migrate for author preference memory, writes files under .story/作者记忆, renders Markdown summaries, and enforces validation and byte-budget rules. While 'manage author habits' is partially aligned, the broader declared purpose is not accurate for this code chunk because the routing/orchestration, dashboard, and update features are absent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
2. 从当前已加载的 `story` skill 目录定位 `scripts/dashboard-server.mjs`,不要硬编码仓库路径、

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares no explicit tool restrictions while instructing use of shell, file read/write, environment inspection, network access, and long-running processes. In a routing skill with broad natural-language triggers, this expands the blast radius: a casual invocation could lead to filesystem changes, process launch, or network activity without clear sandbox boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad natural-language triggers such as generic writing-related phrases can cause the skill to activate unexpectedly. Because this skill can route into file operations, shell commands, dashboard startup, and update checks, overbroad activation materially raises the chance of unintended high-impact actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Allowing activation/routing via generic natural-language references to skills without strong constraints can be abused to steer the agent into higher-risk subskills unexpectedly. In a multi-skill environment, ambiguous routing increases prompt-injection and accidental-execution exposure, especially when some downstream skills may have broader capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions direct the agent to start a local server and potentially open a browser, but they do not require a prominent user warning that a persistent local process will be launched and a URL exposed locally. Even when bound to 127.0.0.1, starting services can consume resources, expose sensitive workspace contents to the local machine, and surprise users who only asked for information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill presents itself primarily as a router/dashboard entrypoint but also includes version-check and installation logic, including a global update command. Hidden or secondary administrative behaviors increase the chance that users invoke software-modifying actions under a less risky mental model than warranted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The update workflow performs network access and package installation but does not foreground the operational risk of executing external commands that modify the installed tool. This is especially sensitive because the install command is global, so a mistaken confirmation can alter the user's environment beyond the current project.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
用户问"有没有新版本""检查更新""升级"时执行。**只通知,更不更新由用户定,不自动安装。**

1. **当前版本**:读本 skill 同目录的 `VERSION` 文件;缺失则视为未知。
2. **最新版本**:优先 `gh release view --json tagName,name,url -R zenstory-ai/oh-story-claudecode` 取 `tagName`;无 gh 用 `curl -fsS --max-time 5 https://api.github.com/repos/zenstory-ai/oh-story-claudecode/releases/latest` 取 `.tag_name`(jq 或 grep)。查不到 → 告知"暂时拉不到最新版本,可手动看 [Releases](https://github.com/zenstory-ai/oh-story-claudecode/releases)",不报错。
3. **比较**:去掉 `v` 前缀按语义版本比(major.minor.patch)。`gh release` 默认取 latest 稳定版,不含 pre-release。
4. **告知**:
   - 已最新 → 「已是最新版 vX.Y.Z」。

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Embedding software installation capability inside a general-purpose story-routing skill violates least surprise and least privilege. Even though the text says not to auto-update, the presence of install logic in a broadly triggered entry skill increases the risk of accidental or socially engineered execution of package-management commands.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The update path runs npx skills add zenstory-ai/oh-story-claudecode -y -g without pinning a specific version, so behavior depends on whatever package/version is current at execution time. This creates a supply-chain and integrity risk: a compromised upstream release or unexpected breaking change could be installed globally from a routine update prompt.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This JavaScript file presents user-facing text in Chinese and later uses a fixed zh-CN locale for number formatting, indicating the skill forces a specific language/locale. The policy allows locale constraints only when user choice or clear justification is provided, which is not present in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This HTML defines a user-facing control to delete the current file, but the surrounding UI text in this file provides no confirmation dialog, warning, or explanatory disclosure about the destructive action. For code/markup reviewed under missing user warnings, destructive operations should have some visible user disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

该行用一长串自然语言条件描述“本文件只在下列情况读”,既包含明确短语“整理作者记忆”,也包含大量状态性/情境性条件,如“碰到升级前留下的旧条目”“冲突候选要落定”等,但没有给出排除条件或清晰的触发边界。这种描述对何时应读取本技能文件缺乏足够约束,容易在相邻任务场景下被过度激活。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file instructs the agent to reply in a specific Chinese wording and format, including fixed Chinese phrases for confirmations and warnings. This imposes a language/locale constraint on user-facing output without any opt-in or explanation that the skill is only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code explicitly forces zh-CN collation for sorting, which is a natural-language/locale policy decision embedded in the implementation. The file also contains multiple Chinese-only user-facing messages and query normalization tied to zh-CN, but does not provide any user choice or opt-in for locale selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The search path normalizes user queries with toLocaleLowerCase("zh-CN"), enforcing a specific locale for text handling. Because this affects user-visible behavior across all runs and no locale choice is exposed, it fits the policy category for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description, trigger phrases, and operational instructions are all presented in Chinese and presume Chinese-language interaction. There is no indication that the user can opt into another language or that the locale restriction is required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code explicitly uses Intl.NumberFormat("zh-CN") for all numeric display, which enforces a locale choice on every user. Because no opt-in, fallback to user preference, or documented regional limitation is shown, this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN" and all visible interface text is in Chinese, with no indication in this file that users can choose another language or that the locale restriction is intentional and documented. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The font stacks prominently prioritize Simplified Chinese font families such as "PingFang SC", "Hiragino Sans GB", "Microsoft YaHei", "Songti SC", and related CJK serif fonts. Because the file does not indicate this is a China-specific or Chinese-language-only skill, this can be read as enforcing a locale-specific presentation choice without documented user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/dashboard-server.mjs:917